Malware

Malware.Heuristic.2038 information

Malware Removal

The Malware.Heuristic.2038 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.Heuristic.2038 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the shellcode get eip malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.Heuristic.2038?


File Info:

name: FAA41850C76192412A4C.mlw
path: /opt/CAPEv2/storage/binaries/f9e825962416024548e4cdbf1a3d2b39745c18f3798c0d0b98598eebd6152459
crc32: 64C7A81F
md5: faa41850c76192412a4cd7d279b26c6a
sha1: 7d353dc36dfdfcf305e98020f3fd86be9590ad3f
sha256: f9e825962416024548e4cdbf1a3d2b39745c18f3798c0d0b98598eebd6152459
sha512: f78c71b62e14bf0b6c69a413a1bfd17341f0e9990bb9e8f5cb9b152a9e7583aa727c74f082176f8908298e449e94ebd7262f941b2fa076bb9bd4befe3fb4896d
ssdeep: 98304:Xfhuvfb6qJ4egoNxg3r3TeOm2rL/y7HFH4OvKVpJ6VDb302kNErf/iPjBo8Ouine:GfbhJlgMpOm2/ENvS6tkt0ne6fC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3563383DB41AF21E11AFDB714343D4ECF4A01279B9A9C5FC1E49CB1E2067D54B8AD8A
sha3_384: 8c8dfac27ea68ae7b6bc0c5051ad71869687e1d8d300fec8345f5425e8a42428439d2f11564a2d031c177c7fee3031b5
ep_bytes: eb04e8d0e79850eb051ab7d8aec3e814
timestamp: 2016-05-26 07:56:22

Version Info:

CompanyName:
FileDescription: _geolib
FileVersion: 1, 0, 0, 2
InternalName: _geolib
LegalCopyright: Copyright (C) 2016
OriginalFilename: _geolib.rc
ProductName: _geolib
ProductVersion: 6, 16, 0, 0
Translation: 0x040c 0x04e4

Malware.Heuristic.2038 also known as:

LionicTrojan.Win32.Generic.lMzB
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.faa41850c7619241
Cylanceunsafe
SangforTrojan.Win32.Agent.Vru5
K7AntiVirusUnwanted-Program ( 0050b9b31 )
K7GWUnwanted-Program ( 0050b9b31 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/GameHack.BFM potentially unsafe
CynetMalicious (score: 100)
TrendMicroPossible_Virus
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Puwaders
XcitiumMalware@#1rl7pebqilc1v
GDataWin32.Application.GameMod.O3Q87S
VBA32BScope.TrojanSpy.Stealer
MalwarebytesMalware.Heuristic.2038
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R002H0CCV21
YandexTrojan.Igent.bWQcYY.9
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic_PUA_HN!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Malware.Heuristic.2038?

Malware.Heuristic.2038 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment