Malware

Malware.AI.2938904392 (file analysis)

Malware Removal

The Malware.AI.2938904392 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2938904392 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2938904392?


File Info:

name: CF4FF4FA6E85655031F6.mlw
path: /opt/CAPEv2/storage/binaries/b57577b33b4639ac0c0ad026cb885bb1ea3f123d34170006707f82643ac654dc
crc32: 04804CEA
md5: cf4ff4fa6e85655031f6db45b36b7526
sha1: aaa0ce1d9b5787b0b25a9f04780e54c9e98230ce
sha256: b57577b33b4639ac0c0ad026cb885bb1ea3f123d34170006707f82643ac654dc
sha512: 2d2ebeaf58538120755db125bb6e829f37d1badc11b53d317d7707e1c1719f059e19c503416d1c412be1667c31262d9767eae9e44e7635256a07cf5075ad927c
ssdeep: 1536:75rnVmg+tFj/0mcN57G7d3Dvzj4LKD2GsfvH3NdYA8vUi5L0jBq5:75rVmg+tmmW7Gx3HkLUI9dSUi5LqBQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2A37B127A90C0B2C0562D304856DBB19B7EF9321B79D587BB941B7EDF702C19A3728B
sha3_384: c68783fd86c4015ea66ad131e2fd976f3d23ddfaa211800115439b665b47f79b69e3f27fb89dfb7c4fa5d196258286d3
ep_bytes: e87c6d0000e979feffffcccccccccccc
timestamp: 2015-08-13 11:41:33

Version Info:

CompanyName: Microsoft © Windows
FileDescription: Spooler Application
FileVersion: 16, 95, 2156, 456
InternalName: spooler
LegalCopyright: Microsoft Windows © 2013
OriginalFilename: splsrv.exe
ProductName: Spooler Application
ProductVersion: 16, 195, 2356, 476
Translation: 0x4009 0x04b0

Malware.AI.2938904392 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.mBLK
DrWebTrojan.DownLoader15.50842
MicroWorld-eScanTrojan.Agent.BLXP
McAfeeGenericRXVQ-TG!CF4FF4FA6E85
MalwarebytesMalware.AI.2938904392
VIPRETrojan.Agent.BLXP
SangforTrojan.Win32.Small.Vrs1
K7AntiVirusTrojan ( 005a3ac21 )
AlibabaTrojan:Win32/Spaeshill.5f62d45e
K7GWTrojan ( 004e07eb1 )
Cybereasonmalicious.a6e856
BitDefenderThetaAI:Packer.663AB31420
VirITTrojan.Win32.DownLoader15.CXFM
CyrenW32/Agent.FSI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Small.NPF
APEXMalicious
ClamAVWin.Trojan.Agent-6827379-0
KasperskyUDS:Trojan.Win32.Johnnie
BitDefenderTrojan.Agent.BLXP
AvastWin32:Numeriq-AC [Trj]
TencentTrojan-Dropper.Win32.Dapato.hc
EmsisoftTrojan.Agent.BLXP (B)
F-SecureHeuristic.HEUR/AGEN.1303379
TrendMicroTROJ_GEN.R002C0DEJ23
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.cf4ff4fa6e856550
SophosMal/Generic-R
IkarusTrojan.Win32.Small
GDataTrojan.Agent.BLXP
JiangminTrojan/Agentb.bqj
AviraHEUR/AGEN.1303379
MAXmalware (ai score=82)
ArcabitTrojan.Agent.BLXP
ZoneAlarmUDS:Trojan.Win32.Johnnie
MicrosoftTrojan:Win32/Spaeshill
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Spaeshill.C5395408
VBA32Trojan.Downloader
ALYacTrojan.Agent.BLXP
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEJ23
RisingTrojan.Small!8.A9 (TFE:5:cJKroxrM0DO)
YandexTrojan.GenAsa!LCR9Zd2YZSU
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Small.NPF!tr
AVGWin32:Numeriq-AC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2938904392?

Malware.AI.2938904392 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment