Malware

JS.Application.EatMemory.A information

Malware Removal

The JS.Application.EatMemory.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JS.Application.EatMemory.A virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine JS.Application.EatMemory.A?


File Info:

name: 863CAD3C0766651B7AFC.mlw
path: /opt/CAPEv2/storage/binaries/88e976d46745585a02ad0823096e8cbead66e775fa70c0ff3372bc538f6302f9
crc32: 9275A7E4
md5: 863cad3c0766651b7afc7d2d6c40ab3c
sha1: 879ebc85f594ecb7561764dae35334e98d810ef9
sha256: 88e976d46745585a02ad0823096e8cbead66e775fa70c0ff3372bc538f6302f9
sha512: e4c91845074b4b8a6e4941651264eacd1f261dda420ca50870139dff01b5a9c632fbe2743b74c8190d335a13c46a1af55bdce582aff50ba48af89890f18bedda
ssdeep: 98304:M1UUaIt/V/fGtNBj+Xi48HsRyrf30R/TDSMG8B9WZ1HiygbpeKcmhFimsU:MCuYV+XjOayrfOGMG89I1HLgoKdio
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D363304B8B4D9B6D0EDA970952557780824FE340F3AEA8BCF41E1B6B5332C55D29E3B
sha3_384: 4023f4c85f5d70691d5deb785cf6ad0f351fed0dc9524a441727392796104f0f3cfadd02ae5f1e11e4955263b2556c01
ep_bytes: 558bec6aff68402141006868ec400064
timestamp: 1998-03-26 14:31:20

Version Info:

CompanyName: InstallShield Software Corporation
FileDescription: PackageForTheWeb Stub
FileVersion: 2.02.001
InternalName: STUB.EXE
LegalCopyright: Copyright © 1996 InstallShield Software Corporation
OriginalFilename: STUB32.EXE
ProductName: PackageForTheWeb Stub
ProductVersion: 2.02.001
Translation: 0x0409 0x04b0

JS.Application.EatMemory.A also known as:

BkavW32.Common.ACF6716D
LionicTrojan.Win32.EatMemory.4!c
FireEyeJS.Application.EatMemory.A
CAT-QuickHealTrojan.Loop
SkyhighArtemis!Trojan
McAfeeArtemis!863CAD3C0766
MalwarebytesFloxif.Virus.FileInfector.DDS
AlibabaTrojan:JS/SixButtons.46e6169c
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MulDrop3.BVNK
ESET-NOD32JS/SixButtons.A
BitDefenderJS.Application.EatMemory.A
AvastFileRepMalware [Trj]
EmsisoftJS.Application.EatMemory.A (B)
GoogleDetected
VIPREJS.Application.EatMemory.A
GDataJS.Application.EatMemory.A
MAXmalware (ai score=99)
XcitiumMalware@#2kf3r6ho5znci
ArcabitJS.Application.EatMemory.A
ALYacJS.Application.EatMemory.A
Cylanceunsafe
PandaGeneric Malware
IkarusTrojan.JS.Winbomb
MaxSecureTrojan.Malware.1516858.susgen
FortinetAdware/SixButtons
AVGFileRepMalware [Trj]
Cybereasonmalicious.c07666
DeepInstinctMALICIOUS
alibabacloudTrojan:Javascript/SixButtons.A

How to remove JS.Application.EatMemory.A?

JS.Application.EatMemory.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment