Malware

Application.Generic.3110137 (B) malicious file

Malware Removal

The Application.Generic.3110137 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3110137 (B) virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Generic.3110137 (B)?


File Info:

name: 9D050FEFC2B2883350ED.mlw
path: /opt/CAPEv2/storage/binaries/1a05e5af02843162a44c14443f160ecc670420b7e18fb0a6424bcc93d45d883c
crc32: BA1E860F
md5: 9d050fefc2b2883350ed969b57b95142
sha1: 01cb0b3b9f984f64139a674b78ba4127a8c35a0b
sha256: 1a05e5af02843162a44c14443f160ecc670420b7e18fb0a6424bcc93d45d883c
sha512: 9e775693f308bd000bce39bcdb06c2605ee5fd9180bc282c3d26e4826a9703bb197cbc8c697e18168886990935b8430b8c3a9f19abf18c9bfd0bb640f5f8dfef
ssdeep: 24576:Ond0kJOMmGYiSWm6Bt4Cp/1jq7zevZQ/qVxyWVGlvBSVmTEaa3zfGh8W+sF0mMSK:IdxYiTcm/1j/7XGYk80YSinZJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8552318BFA8D872C0185D766F06CBB53420BE50A134572797F67F5B293F3266868C2B
sha3_384: 2012cd5f8514efdecb544296807f80a9183a401c6c3622087252cfdad1708f2f7df5abc60f05dfeb5d005cbafbfbd937
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-29 09:42:03

Version Info:

Comments: 健康助手
CompanyName:
FileDescription: 健康助手
FileVersion: 1.0.1.1
InternalName: 健康助手
LegalCopyright: (C)
ProductName: 健康助手
ProductVersion: 1.0.1.1
Translation: 0x0804 0x03a8

Application.Generic.3110137 (B) also known as:

BkavW32.AIDetect.malware1
LionicAdware.NSIS.Xpyn.2!c
Elasticmalicious (high confidence)
DrWebTrojan.KillFiles.28526
MicroWorld-eScanApplication.Generic.3110137
FireEyeGeneric.mg.9d050fefc2b28833
CAT-QuickHealTrojan.MauvaiseRI.S5245166
McAfeeArtemis!9D050FEFC2B2
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Convagent.15ead150
VirITTrojan.Win32.KillFiles.BQFE
CyrenW32/NSISMod.A.gen!Eldorado
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CDK22
Paloaltogeneric.ml
ClamAVWin.Adware.Xpyn-9940467-0
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
BitDefenderApplication.Generic.3110137
NANO-AntivirusRiskware.Win32.ShouQu.dmnfjx
AvastWin32:Adware-gen [Adw]
TencentNsis.Adware.Convagent.Htlt
Ad-AwareApplication.Generic.3110137
EmsisoftApplication.Generic.3110137 (B)
ZillyaAdware.Convagent.Win32.1460
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.tc
SophosGeneric PUA AB (PUA)
SentinelOneStatic AI – Malicious PE
GDataApplication.Generic.3110137
JiangminAdWare.NSIS.bqy
MAXmalware (ai score=71)
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
MicrosoftTrojan:Win32/Sabsik.TE.A!ml
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win.Xpyn.R458557
Acronissuspicious
VBA32Adware.NSIS.Xpyn
ALYacApplication.Generic.3110137
MalwarebytesTrojan.Crypt
APEXMalicious
RisingMalware.NSISMod!1.DBC4 (CLASSIC)
YandexTrojan.GenAsa!hrZneoTQ9ng
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.4685!tr
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_90% (W)

How to remove Application.Generic.3110137 (B)?

Application.Generic.3110137 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment