Malware

Should I remove “Win32:Numeriq-AC [Trj]”?

Malware Removal

The Win32:Numeriq-AC [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Numeriq-AC [Trj] virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:Numeriq-AC [Trj]?


File Info:

name: 2E3C2BC14EDC313BEA26.mlw
path: /opt/CAPEv2/storage/binaries/5f9f622570fc00ec17435fc4b64e19c217b0d5eb5d7fbdf4cec973c1b8da9103
crc32: F6AACE09
md5: 2e3c2bc14edc313bea26172fbd562fae
sha1: 2a97372a5cdabc7304af9a75a6ba816aaec66f87
sha256: 5f9f622570fc00ec17435fc4b64e19c217b0d5eb5d7fbdf4cec973c1b8da9103
sha512: 032a633d2c174e8d25c5b92657a406cdf4caf4283ccba072b64171d7596c40dd036dbe42df23201fb703dc5ddaf0e522e3eb0945ad939d699c4caaaf3e1ea2f0
ssdeep: 1536:K5rnVmg+tFj/4wcN57G7d3Dvzj4LKD2GsfvH3NdYA8vUi5L0jBUQ:K5rVmg+tPW7Gx3HkLUI9dSUi5LqB7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171A37B127A90C0B2C0562D304856DBB19B7EF5321B79D587BB940B7EDF702C29A3729B
sha3_384: 8cb74ade4add08d4f5a6b30ce8dd60fb26b4ba61dcb4ba1563cd5a20b1be636ad0812cc7f70bf9dd32507fa603cbc19e
ep_bytes: e87c6d0000e979feffffcccccccccccc
timestamp: 2015-08-13 11:41:33

Version Info:

CompanyName: Microsoft © Windows
FileDescription: Spooler Application
FileVersion: 16, 95, 2156, 456
InternalName: spooler
LegalCopyright: Microsoft Windows © 2013
OriginalFilename: splsrv.exe
ProductName: Spooler Application
ProductVersion: 16, 195, 2356, 476
Translation: 0x4009 0x04b0

Win32:Numeriq-AC [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.mBLK
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BLXP
ClamAVWin.Trojan.Agent-6827379-0
FireEyeGeneric.mg.2e3c2bc14edc313b
ALYacTrojan.Agent.BLXP
MalwarebytesSmall.Trojan.Agent.DDS
ZillyaTrojan.Small.Win32.94616
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Spaeshill.ed7b1468
K7GWRiskware ( 0040eff71 )
K7AntiVirusTrojan ( 005a3ac21 )
BitDefenderThetaGen:NN.ZexaF.36250.gy1@amu9yIni
VirITTrojan.Win32.DownLoader15.CXFM
CyrenW32/Agent.FSI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Small.NPF
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Johnnie
BitDefenderTrojan.Agent.BLXP
AvastWin32:Numeriq-AC [Trj]
TencentTrojan-Dropper.Win32.Dapato.hc
EmsisoftTrojan.Agent.BLXP (B)
F-SecureHeuristic.HEUR/AGEN.1303379
DrWebTrojan.DownLoader15.50842
VIPRETrojan.Agent.BLXP
TrendMicroTROJ_GEN.R002C0DE723
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
SophosMal/Generic-R
GDataTrojan.Agent.BLXP
JiangminTrojan/Agentb.bqj
AviraHEUR/AGEN.1303379
ArcabitTrojan.Agent.BLXP
ZoneAlarmUDS:Trojan.Win32.Johnnie
MicrosoftTrojan:Win32/Spaeshill
GoogleDetected
AhnLab-V3Trojan/Win.Spaeshill.C5395408
McAfeeGenericRXVQ-TG!2E3C2BC14EDC
MAXmalware (ai score=83)
VBA32Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DE723
RisingTrojan.Small!8.A9 (TFE:5:cJKroxrM0DO)
YandexTrojan.GenAsa!LCR9Zd2YZSU
IkarusTrojan.Win32.Small
FortinetW32/Small.NPF!tr
AVGWin32:Numeriq-AC [Trj]
Cybereasonmalicious.14edc3
DeepInstinctMALICIOUS

How to remove Win32:Numeriq-AC [Trj]?

Win32:Numeriq-AC [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment