Malware

Application.Generic.3026556 (file analysis)

Malware Removal

The Application.Generic.3026556 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3026556 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Application.Generic.3026556?


File Info:

name: C8E699D9B3ACF285BBCA.mlw
path: /opt/CAPEv2/storage/binaries/f366d9e2355442c46b5705976d9ee54276724c929bd19145e23a5330f84a5499
crc32: F82E0C37
md5: c8e699d9b3acf285bbcaf21d8ca08048
sha1: 916116bd1fa9e1e8e57a24afdd9ef947ab6dfe5b
sha256: f366d9e2355442c46b5705976d9ee54276724c929bd19145e23a5330f84a5499
sha512: 40db7e69e76ee0d54f8bacdd4dc4a7a331a6394f17b3e04b5a1adcf72f4406061f6e906bf5494320363170e997814186946fdfefb289a187ae33c808052b6f7d
ssdeep: 12288:9Pr745+G0KZktF5sjJZaqvucDJ718l78qXUi/z2bMcgZpANun+ceJW:xIDNOmguubPabMpyc+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EA0523EE1340626FC24916FE1E73BFBA8D2347DA5D63A3504BB116C227A1AF45B51C34
sha3_384: 62006042b8f11cabb7747be6d96b473362e80101e7c0c0039f167f084a807cafdc37e578c1e254e8660639409af741b1
ep_bytes: be000000005081ea10ab1064683487f7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Application.Generic.3026556 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3026556
FireEyeApplication.Generic.3026556
ALYacApplication.Generic.3026556
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1239224
SangforTrojan.Win32.Injector.DZQA
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Injector.a0b1580e
K7GWTrojan ( 005762bf1 )
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderApplication.Generic.3026556
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosML/PE-A + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJ221
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftApplication.Generic.3026556 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.wzp
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=79)
Antiy-AVLTrojan/Generic.ASBOL.C690
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
GDataApplication.Generic.3026556
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369407
McAfeeGenericRXAA-FA!C8E699D9B3AC
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
TrendMicro-HouseCallTROJ_GEN.R002C0DJ221
RisingTrojan.Kryptik!1.D12D (CLOUD)
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aq0sP!h
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Generic.3026556?

Application.Generic.3026556 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment