Malware

What is “Malware.AI.2957937952”?

Malware Removal

The Malware.AI.2957937952 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2957937952 virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Malware.AI.2957937952?


File Info:

crc32: 956DAE99
md5: 20392ab7994506b208c8d7c13432a8a6
name: 20392AB7994506B208C8D7C13432A8A6.mlw
sha1: 0e108de067e411ddd9de1213e81df499cf15a537
sha256: 2225d10b4e7ca4b31e4cd01afe0f4141b159d32812cf98a15701c2bbb633c896
sha512: 0dda68ac1ee0e56e9970fa7552ffe079895ed08b0aacda52f7c154ff0d07c710d0a48c49cc89e28eec4974eea635b64b3c610a11d56b446233a27bcacdcf9005
ssdeep: 6144:mdVo7FjLTsbF14pHoFN6WtljaJul+pyd8:mdVo5WQpHoFN6WtljaElIG8
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: MyPad
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MyPad Application
ProductVersion: 1, 0, 0, 1
FileDescription: MyPad MFC Application
OriginalFilename: MyPad.EXE
Translation: 0x0409 0x04b0

Malware.AI.2957937952 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057b02c1 )
Elasticmalicious (high confidence)
ALYacDeepScan:Generic.Rincux2.CD2E400E
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 0057b02c1 )
Cybereasonmalicious.799450
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.ESRI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:Backdoor.Win32.Farfli
BitDefenderDeepScan:Generic.Rincux2.CD2E400E
MicroWorld-eScanDeepScan:Generic.Rincux2.CD2E400E
Ad-AwareDeepScan:Generic.Rincux2.CD2E400E
ComodoTrojWare.Win32.Magania.A@5wdy5u
BitDefenderThetaGen:NN.ZexaF.34678.wmLfaWtj0bii
TrendMicroBackdoor.Win32.ZEGOST.SMAL02
McAfee-GW-EditionBehavesLike.Win32.Downloader.ft
FireEyeGeneric.mg.20392ab7994506b2
EmsisoftDeepScan:Generic.Rincux2.CD2E400E (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Farfli.DSK!MTB
ArcabitDeepScan:Generic.Rincux2.CD2E400E
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataDeepScan:Generic.Rincux2.CD2E400E
McAfeeArtemis!20392AB79945
MAXmalware (ai score=85)
MalwarebytesMalware.AI.2957937952
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMAL02
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazqEomtqFB+lXNopkxk7amH4)
IkarusTrojan.Win32.Farfli
FortinetW32/GenKryptik.EOZH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.2957937952?

Malware.AI.2957937952 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment