Malware

Application.Generic.3079441 (file analysis)

Malware Removal

The Application.Generic.3079441 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3079441 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Collects information about installed applications

How to determine Application.Generic.3079441?


File Info:

name: D179250F3042B4BF237F.mlw
path: /opt/CAPEv2/storage/binaries/1700be28922f712fa449fa4eb78b611318d24a09171c0eb2810978ea3a862d29
crc32: 3CB04C89
md5: d179250f3042b4bf237f780997a971a8
sha1: ad16743e7dc2480646e81e7e3a2b9d97e2ae3489
sha256: 1700be28922f712fa449fa4eb78b611318d24a09171c0eb2810978ea3a862d29
sha512: 2f9765b73e5222a7771554ecf5d7ce8347fae7e40346f81a529e7c1e53a5edbb568755cba90a53da113e86a932d1686818768eed7da45b207c154717a6bee823
ssdeep: 196608:EqJmxAPzuSubd//c5tAJc949G4AyPsZLGYU9Tb7biSiT4KMhC:EqTzB42tmc94Q4AyPNYwbST4KMc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE8633AB3291E165EA3B5971AA91DBB2E801BC1A0E30B04BF5613F5F38757537C0A707
sha3_384: c44d6b0ef484ed4c0cfc41d82c72d4d70b332ff78da16bcca42ebebd383412e39312d54dfff1f266145b387009445c0a
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2019-12-16 00:54:10

Version Info:

Comments:
CompanyName: Alcohol Soft Development Team
FileDescription: Alcohol 120% v2.1.1.1019
FileVersion: 2.1.1.1019
LegalCopyright: © Alcohol Soft Development Team
ProductName: Alcohol 120% v2.1.1.1019
Translation: 0x0409 0x04b0

Application.Generic.3079441 also known as:

LionicAdware.NSIS.AdPack.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3079441
FireEyeApplication.Generic.3079441
ALYacApplication.Generic.3079441
CylanceUnsafe
ZillyaAdware.AdPack.Win32.70
SangforRiskware.Win32.AdPack.gen
K7AntiVirusTrojan ( 005850dc1 )
AlibabaAdWare:Win32/AdPack.fc4a3101
K7GWTrojan ( 005850dc1 )
SymantecPUA.Gen.2
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:AdWare.NSIS.AdPack.gen
BitDefenderApplication.Generic.3079441
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Adrepack.Wpjd
Ad-AwareApplication.Generic.3079441
EmsisoftApplication.Generic.3079441 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosGeneric PUA KN (PUA)
GDataWin32.Trojan.Agent.94OXXQ
JiangminTrojan.Generic.gwsls
AviraTR/Redcap.juayq
ViRobotTrojan.Win32.Z.Sabsik.8417021
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!D179250F3042
MAXmalware (ai score=70)
VBA32Adware.AdPack
TrendMicro-HouseCallTROJ_GEN.R002H0CJO21
RisingTrojan.Generic@ML.97 (RDMK:YsZN5k40vUG3G2APSbieug)
IkarusTrojan.Win32.Adrepack
MaxSecureTrojan.Malware.121115918.susgen
BitDefenderThetaGen:NN.ZedlaF.34294.au8@a4rMv!ic
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Application.Generic.3079441?

Application.Generic.3079441 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment