Malware

Application.Generic.3157975 removal guide

Malware Removal

The Application.Generic.3157975 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3157975 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Application.Generic.3157975?


File Info:

name: 606097C3D4F9E5435807.mlw
path: /opt/CAPEv2/storage/binaries/cd438ea91621f620bd63b1e1069005750509565c118c3602bf314fd3f98c4281
crc32: 591A2E53
md5: 606097c3d4f9e54358078ef0563647f5
sha1: c410edc2905f2370a7c1b69156a941cac65ee36b
sha256: cd438ea91621f620bd63b1e1069005750509565c118c3602bf314fd3f98c4281
sha512: 9e4afa6764c5ecc85b317d3fdd5dcf0211b44e5036d2ba06f0ad424cc9bb87dbc9397a770f9a502376940d2ccdfee27988ac8701325ac8d23ad4bba8549d3681
ssdeep: 12288:xhkDgouVv2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4aql:/RNJkcoQricOIQxiZY1iae
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119969F31F6C68036C2B323B19E7EF7A9973D79361326D19B37C82E215E604416B29727
sha3_384: 4a058f93f7d8d5833c4d5a3b2a0ee7ff9e417cef8e315307e7af6181da0a6f93e7b8248fe33515e9efda0a59a14d0e01
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Application.Generic.3157975 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanApplication.Generic.3157975
FireEyeGeneric.mg.606097c3d4f9e543
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaPacked:Win32/Genome.f06f1c5f
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Autoit.Q suspicious
APEXMalicious
TrendMicro-HouseCallMal_Utoti4
BitDefenderApplication.Generic.3157975
AvastWin32:Evo-gen [Trj]
Ad-AwareApplication.Generic.3157975
EmsisoftApplication.Generic.3157975 (B)
VIPREApplication.Generic.3157975
TrendMicroMal_Utoti4
McAfee-GW-EditionBehavesLike.Win32.Dropper.rz
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Genome
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=79)
Antiy-AVLTrojan/Win32.AutoRun.inf
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.Agent.TJD2AY
CynetMalicious (score: 100)
McAfeeArtemis!606097C3D4F9
RisingTrojan.Generic@AI.100 (RDMK:ohwTiyiGOpCnfzWk5wjobg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Autoit.AZA
FortinetRiskware/Mal_Utoti4
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.2905f2

How to remove Application.Generic.3157975?

Application.Generic.3157975 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment