Malware

Malware.AI.520739368 removal guide

Malware Removal

The Malware.AI.520739368 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.520739368 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Network activity detected but not expressed in API logs
  • CAPE detected the RemoteUtilitiesRAT malware family
  • Collects information to fingerprint the system

Related domains:

wpad.local-net
s1.symcb.com

How to determine Malware.AI.520739368?


File Info:

name: 90E027B39D2786D5B465.mlw
path: /opt/CAPEv2/storage/binaries/99de2f7653107a227a79993aeb03b1bb443b66376c49ec590cf3a91d6cf184c8
crc32: DD51C44A
md5: 90e027b39d2786d5b465a9dc53bf040e
sha1: 5a9d6b1fcdaf4b2818a6eeca4f1c16a5c24dd9cf
sha256: 99de2f7653107a227a79993aeb03b1bb443b66376c49ec590cf3a91d6cf184c8
sha512: 097264ae7a20e90aaacda0546082c466aa90922c9242044cdb08d81953022164cda439c7fa9cbd989f73beafbd4d58b54fc1db6afa66f8ad4d446d06c17fc779
ssdeep: 98304:gBkwl/csN9uTkl8gdghhKHQuPjbICG00SWtL1lXQ/8BCdJYuhR:g1ei8gdghhKHQurw1lg/BP/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A668D1ABB84223ED0770A3A497FD75C993F7BA12E16CC1B67F4094C4E3A6406D2B647
sha3_384: ceb3520ab3c85e636416505a9e02ccd4f64d799524236cedfc2a7b48a09b7cce374ce63aa38db117108568641d9ea25e
ep_bytes: 558bec83c4f0b8cc9b9100e840c3adff
timestamp: 2015-05-08 01:19:34

Version Info:

CompanyName: Usoris Systems LLC
FileDescription: Remote Utilities
FileVersion: 6.3.0.1
LegalCopyright: Copyright © 2015 Usoris Systems LLC All rights reserved.
LegalTrademarks: Usoris Systems LLC, Remote Utilities
ProductName: Remote Utilities
ProductVersion: 6.3.0.1
InternalName: Remote Utilities part
Comments: Modified by an unpaid evaluation copy of Resource Tuner Console 2 (www.heaventools.com)
Translation: 0x0409 0x04e4

Malware.AI.520739368 also known as:

LionicRiskware.Win32.RemoteUtils.1!c
MicroWorld-eScanGen:Variant.Application.RemoteUtils.1
FireEyeGeneric.mg.90e027b39d2786d5
ALYacGen:Variant.Application.RemoteUtils.1
CylanceUnsafe
ZillyaTool.RemoteUtilities.Win32.273
SangforTrojan.Win32.Wacatac.A
CrowdStrikewin/malicious_confidence_100% (D)
K7GWUnwanted-Program ( 004b9ffe1 )
K7AntiVirusUnwanted-Program ( 004b9ffe1 )
ESET-NOD32a variant of Win32/RemoteAdmin.RemoteUtilities.I potentially unsafe
APEXMalicious
BitDefenderGen:Variant.Application.RemoteUtils.1
NANO-AntivirusRiskware.Win32.RemoteAdmin.evrsgt
Ad-AwareGen:Variant.Application.RemoteUtils.1
DrWebProgram.RemoteAdmin.753
EmsisoftGen:Variant.Application.RemoteUtils.1 (B)
GDataGen:Variant.Application.RemoteUtils.1
JiangminRemoteAdmin.Agent.ow
GridinsoftRansom.Win32.Wacatac.sa
ViRobotAdware.Agent.6504888
MAXmalware (ai score=74)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.520739368
YandexTrojan.GenAsa!PWAeoVWBOA8
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/RemoteAdmin_RemoteUtilities
Cybereasonmalicious.39d278
MaxSecureTrojan.Malware.74578839.susgen

How to remove Malware.AI.520739368?

Malware.AI.520739368 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment