Malware

About “Dropped:Application.Generic.95213” infection

Malware Removal

The Dropped:Application.Generic.95213 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Application.Generic.95213 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:13573
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.ezula.com
updates.desktop.virtumundo.com
code.ignphrases.com
ping.180solutions.com
www.igetnet.com
adserv.internetfuel.com
www.triarch.de
app.ezula.com
members.lycos.nl
www.neonapster.com
irc.lightning.net
connect1.gnutellanet.com
lgnukel.dns2go.com
connect2.gnutellanet.com
enterich.reich-gym.de
connect3.gnutellanet.com
flyingsquad.hl.gamigo.de
de.gamigo.com
connect4.gnutellanet.com
public.bearshare.net
www.puterdocs.com
www.cultiv8r.com
pjessup.freeshell.org
www.vertsync.com
www.php50.com
users.ucmore.com
www.exactsearchbar.com
users2.ucmore.com
upgrade.new.tech
upgrade.newdotnet.net
checkin.exactsearchbar.com
server.ipinsight.net
quatrefeuillepolonaise.xyz
www.bing.com

How to determine Dropped:Application.Generic.95213?


File Info:

crc32: 4FF69A86
md5: 372aef900efbd65621a671c9d574c740
name: setupneonapster.exe
sha1: 2eff0b328115c60818f9d3e356f7819e193f298e
sha256: 2e149539edda1ae646524041d2d38fb799d79614490b17c2f6cc3b5446405918
sha512: c3edf63a1747af7dbb10cf733a0cee32910c9efe6635b4cdb4218c9259944698d9eb493c584009879eb443994b37ef59dd1ffa88122fadba91a5f0a146c18e3a
ssdeep: 49152:kodCb9RigSofx9QeFBVXCZGV4cNv2lfx81fITFMbxUvpPTN:kodCB/SyFBVYU4Gv2x81fBUxLN
type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

0: [No Data]

Dropped:Application.Generic.95213 also known as:

CMCAdWare.Win32.EZula!O
Qihoo-360Win32/Trojan.d8b
CylanceUnsafe
VIPREAccelerator
BitDefenderDropped:Application.Generic.95213
Cybereasonmalicious.00efbd
CyrenW32/Adware.PXGK-0338
GDataGen:Adware.Heur.ky8@RC9@l7ni
Kasperskynot-a-virus:AdWare.Win32.Ucmore
AlibabaTrojanDownloader:Win32/TargetSoft.70b3e23b
NANO-AntivirusRiskware.Win32.Ucmore.ebgzxc
ViRobotAdware.Ucmore.2436610
SophosUCMore (PUA)
F-SecureHeuristic.HEUR/AGEN.1008272
DrWebTrojan.MoemoneyAd
FireEyeDropped:Application.Generic.95213
EmsisoftDropped:Application.Generic.95213 (B)
F-ProtW32/Adware.GHZ
AviraTR/Dldr.Agent.dqlzz
ArcabitAdware.Heur.E03EC1
ZoneAlarmnot-a-virus:AdWare.Win32.BargainBuddy.a
MicrosoftTrojanDownloader:Win32/Agent
VBA32AdWare.Ucmore
MAXmalware (ai score=100)
PandaGeneric Malware
ESET-NOD32a variant of Win32/Adware.UCmore.AC
TencentWin32.Adware.Ucmore.Ligw
Ikarusnot-a-virus:AdWare.Win32.Ucmore
AVGNSIS:Ezula [PUP]
AvastNSIS:Ezula [PUP]
MaxSecureTrojan.Malware.1129522.susgen

How to remove Dropped:Application.Generic.95213?

Dropped:Application.Generic.95213 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment