Malware

About “Application.Generic.3593638” infection

Malware Removal

The Application.Generic.3593638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3593638 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Generic.3593638?


File Info:

name: 6FF1FA116579EAA53732.mlw
path: /opt/CAPEv2/storage/binaries/62c4d8f99bce85d2ae1af29acccacb3fa871369bbfa724b62a656627feacfbdf
crc32: 46348EB7
md5: 6ff1fa116579eaa5373220da8bb6df01
sha1: ce57c516f61763aa5a8806574c103137fbed9b71
sha256: 62c4d8f99bce85d2ae1af29acccacb3fa871369bbfa724b62a656627feacfbdf
sha512: 0bad58d612ba0b4b793f034d7b711235e491d7104766355d4ae168b116be98b468ddc9c810a62b551d042e022421be4e41a7d03856d37b71b299ec8dae75e07e
ssdeep: 98304:EDYiDB0nH6uRJ3Vk1KYBYTzyZiTInDG0/psUt+V9zqlDeNgtQ9/:2B0nauR81RuV9zqlDeKtq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E26BF11BE924576E5B3063549AFF33D257DEA20072684D393CC1D699D302E33A3A7AB
sha3_384: d7f27f0a1b657ae301650ef29365354c71834e9cd40c4c7ade73397dd7e8f7e616e32227b0371aac4ed465816981a0f5
ep_bytes: e8240d0000e98efeffffff25241c7300
timestamp: 2021-10-08 10:44:07

Version Info:

CompanyName: 厦门险峰网络科技有限公司
FileDescription: Google Chrome浏览器安装程序
FileVersion: 94.1.4.1
InternalName: SetupChrome
LegalCopyright: Copyright (C) 2021 厦门险峰网络科技有限公司
OriginalFilename: SetupChrome
ProductName: Google Chrome浏览器安装程序
ProductVersion: 94.1.4.1
Translation: 0x0804 0x04b0

Application.Generic.3593638 also known as:

LionicTrojan.Win32.Inject.1b!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3593638
FireEyeApplication.Generic.3593638
McAfeeArtemis!6FF1FA116579
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Inject.Win32.315580
AlibabaTrojan:Win32/Inject.d3707dc3
Cybereasonmalicious.16579e
ESET-NOD32a variant of Win32/Adware.Tongbuxing.A
KasperskyHEUR:Trojan.Win32.Inject.gen
BitDefenderApplication.Generic.3593638
NANO-AntivirusTrojan.Win32.Inject.jqhtzj
F-SecureTrojan.TR/Inject.kxxoa
DrWebTrojan.Siggen17.51296
VIPREApplication.Generic.3593638
TrendMicroTROJ_FRS.0NA103B423
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Tongbuxing
JiangminTrojan.Inject.cahx
AviraTR/Inject.kxxoa
Antiy-AVLTrojan/Win32.Inject
KingsoftWin32.Trojan.Inject.gen
ArcabitApplication.Generic.D36D5A6
ZoneAlarmHEUR:Trojan.Win32.Inject.gen
GDataApplication.Generic.3593638
VaristW32/ABAdware.KHAQ-1288
VBA32Trojan.Inject
ALYacApplication.Generic.3593638
MAXmalware (ai score=73)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_FRS.0NA103B423
TencentMalware.Win32.Gencirc.115d92a5
MaxSecureTrojan.Malware.11926561.susgen
FortinetW32/PossibleThreat
PandaTrj/CI.A
alibabacloudTrojan:Win/Tongbuxing.A

How to remove Application.Generic.3593638?

Application.Generic.3593638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment