Malware

Application.Generic.3027506 removal

Malware Removal

The Application.Generic.3027506 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3027506 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Application.Generic.3027506?


File Info:

name: EBFD999AF8E64132D818.mlw
path: /opt/CAPEv2/storage/binaries/771b0a3b6b4fa4f763fd9a147fd68ca08376398749531b91ada4693c722c8ce3
crc32: BC2BFFD7
md5: ebfd999af8e64132d818dc9a3f1b08b6
sha1: 1b62adc9d49f527c9d40cb90b6bde15737e1b2f1
sha256: 771b0a3b6b4fa4f763fd9a147fd68ca08376398749531b91ada4693c722c8ce3
sha512: 2b20ee2cb7944c3b25a27c2cbb61a1ada09d04169039f5e4ca80e657c76facb299e132d50b17ffa25e3e0f0c22d902708ffc791f61bdd3daba3a2cd1cd93989b
ssdeep: 24576:w8ldLmtfz8VA/cI6yM6p6zMj9pXWSrSWQ7DI2wX:zCfQaBMIrj9pGSrBAD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1810523F3CC41E23AF7DEE9B6AAD436A17E80453223A09A5BF9C25CA1B4FFD563001515
sha3_384: 2cb2880618667f573a0dfed062f2b5a66e2a954b77f6d4473cbbf5f639ea24cac8eaeb141a47e331e942e2ed1ca5b1d5
ep_bytes: 68000000008b042483c4045301ca81e9
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Application.Generic.3027506 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.215
MicroWorld-eScanApplication.Generic.3027506
FireEyeApplication.Generic.3027506
ALYacApplication.Generic.3027506
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3591723
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aylVPzh
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
TrendMicro-HouseCallTROJ_GEN.R002C0DJ221
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderApplication.Generic.3027506
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
EmsisoftApplication.Generic.3027506 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREPacker.NSAnti.Gen (v)
TrendMicroTROJ_GEN.R002C0DJ221
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosML/PE-A + Mal/HckPk-A
IkarusTrojan.Win32.Injector
JiangminRiskTool.BitCoinMiner.wgj
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68D
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataApplication.Generic.3027506
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4302695
McAfeeGenericRXAA-FA!EBFD999AF8E6
MAXmalware (ai score=79)
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Generic.3027506?

Application.Generic.3027506 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment