Malware

What is “Application.Generic.3021542”?

Malware Removal

The Application.Generic.3021542 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3021542 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Generic.3021542?


File Info:

name: 81BAEDA48A62EA4F6302.mlw
path: /opt/CAPEv2/storage/binaries/7d3610c1e624ab785648a20eec92a4bf7339111421b378b8fbbe23fa0f4fce18
crc32: 07B9B202
md5: 81baeda48a62ea4f6302ffbf0e89a21b
sha1: 079e5fecc1f8e611499fc4c99cdadc39d9efef04
sha256: 7d3610c1e624ab785648a20eec92a4bf7339111421b378b8fbbe23fa0f4fce18
sha512: accf70c953b140267e79fd07890df058ea675ccf3b9c9f6e18ab1a4e40e948e7a0a3b3396e9f7b4b39f30ffb92b5aab3dea6a4f427e6b99be589fcd950154b62
ssdeep: 24576:KndKMX5wtYHXqnj36AzMUeIfMNp0/VJGkBym:UdzsYHW36AzM8fMIukd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110352321BAD4C43AE7244D70A64ACF316120FC099791875323E1BF1F6A7BBE2761D26D
sha3_384: 9c25318a19edf5e30d2419151ef8feb70ef61892422646493135bff09e3bc5223ba6e19908e011c800946e67d9ceee69
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-29 09:42:03

Version Info:

Comments: 爱壁纸
CompanyName:
FileDescription: 爱壁纸
FileVersion: 1.0.1.1
InternalName: 爱壁纸
LegalCopyright: (C)
ProductName: 爱壁纸
ProductVersion: 1.0.1.1
Translation: 0x0804 0x03a8

Application.Generic.3021542 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3021542
FireEyeGeneric.mg.81baeda48a62ea4f
CAT-QuickHealTrojan.MauvaiseRI.S5245166
McAfeeArtemis!81BAEDA48A62
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Convagent.c365f682
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CJG21
ClamAVWin.Trojan.691128-1
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
BitDefenderApplication.Generic.3021542
NANO-AntivirusRiskware.Win32.ShouQu.dmnfjx
AvastWin32:Adware-gen [Adw]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareApplication.Generic.3021542
EmsisoftApplication.Generic.3021542 (B)
DrWebTrojan.KillFiles.28526
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
SophosGeneric PUA AH (PUA)
APEXMalicious
GDataApplication.Generic.3021542
JiangminAdWare.NSIS.bqy
MAXmalware (ai score=76)
Antiy-AVLTrojan/Generic.ASBOL.8A95
GridinsoftRansom.Win32.Wacatac.sa
ViRobotAdware.Agent.1074702
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win.Xpyn.R443808
Acronissuspicious
VBA32Adware.NSIS.Xpyn
ALYacApplication.Generic.3021542
RisingAdware.Agent!1.D9F5 (CLASSIC)
YandexTrojan.GenAsa!hrZneoTQ9ng
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.4685!tr
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Application.Generic.3021542?

Application.Generic.3021542 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment