Trojan

Trojan.Generic.35803582 removal guide

Malware Removal

The Trojan.Generic.35803582 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.35803582 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Generic.35803582?


File Info:

name: 8497599C120273056DF6.mlw
path: /opt/CAPEv2/storage/binaries/9022784990e7be6e4fa58b4e35b2627bbd0827cd02a50362eae69571566e766a
crc32: 495F5E43
md5: 8497599c120273056df6f4fdc1cfbae5
sha1: f0ddb95ad86d6c1c52eb05cbdf2d5ed0db99e6d2
sha256: 9022784990e7be6e4fa58b4e35b2627bbd0827cd02a50362eae69571566e766a
sha512: b5e527e276766c73bf509c89f155af4c366733bbd48c4af032722e2fdebb3f9efa0554bf592921f93c8643d23c8ac9f4a44c742e8704bf01337cda5a6eebac33
ssdeep: 49152:qXKgbSUIxUCG4LNcDYH8Grkl5Dm8E0jfzFQ:uJcUQLUGrupm8ECfzFQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166A51202F3D2D0B2E09604B9042A9BB69F757C3157B4C4E7AFD4396E9D303E19A3674A
sha3_384: 364f9efda6d92977a1db769cd50532aeea5ddab10dd7314ef1df0c277f9fd246b7dcca9f98fc135ee85b240e0284ace4
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2018-07-31 13:30:07

Version Info:

Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.5.2.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2018 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFilename: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.5.2.0
Translation: 0x0409 0x04e4

Trojan.Generic.35803582 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Farfli.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.35803582
FireEyeGeneric.mg.8497599c12027305
SkyhighBehavesLike.Win32.BadFile.vc
McAfeeArtemis!8497599C1202
Cylanceunsafe
SangforTrojan.Win32.Farfli.V58i
AlibabaTrojanDropper:Win32/Sufrar.d2b40077
K7GWTrojan ( 005964161 )
K7AntiVirusTrojan ( 005964161 )
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Farfli.CNM.Gen
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R011H0CE224
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Generic.35803582
SophosMal/Generic-S
F-SecureTrojan.TR/Farfli.wzwcw
VIPRETrojan.Generic.35803582
EmsisoftTrojan.Generic.35803582 (B)
IkarusTrojan.Win32.Farfli
AviraTR/Farfli.wzwcw
ArcabitTrojan.Generic.D22251BE
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.Agent.6OTGX8
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Agent.C5617890
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Evasion/SFACTORY!1.EEEF (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Farfli.CNM!tr
alibabacloudTrojan[dropper]:Win/Sufrar.gyf

How to remove Trojan.Generic.35803582?

Trojan.Generic.35803582 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment