Malware

About “Application.Generic.3095451” infection

Malware Removal

The Application.Generic.3095451 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Generic.3095451 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Application.Generic.3095451?


File Info:

name: 47EB12E59C0F46F45A54.mlw
path: /opt/CAPEv2/storage/binaries/b79beff0c53848d98dc5552e671db63abb952d2a5208d28b5ce53c932c26bc31
crc32: 704E51B0
md5: 47eb12e59c0f46f45a54f0300306f325
sha1: 2f29f29795a4e19f437d3eab70cd795e9b1a86a3
sha256: b79beff0c53848d98dc5552e671db63abb952d2a5208d28b5ce53c932c26bc31
sha512: 7d1993d1f1aaf95f677c1c9f18102ffbe8fce225e21423400b365f5d2ea8018f86a5527d0b6051fc562cb68e758ed22e5dbebfaf93f776f9fa66ad4e1ae6fe92
ssdeep: 49152:I0GokR52R84EbgoQRD3JbCU48br85vEW:g72RFEb8JmU4M8P
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E57533B07913D9F4CBB743BC479A6723CFC1CA391A5C9867864436289E3039D1D68E9B
sha3_384: 033bf4912545eaf1dab4885ef5447137e6d867b8e218cbf2037526431ae38ef6a3c313c10a9e1d57330ec873438db31b
ep_bytes: ba0000000083ec04891c2481c0f3d3ae
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Application.Generic.3095451 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3095451
FireEyeApplication.Generic.3095451
McAfeeGenericRXOS-KI!47EB12E59C0F
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.795a4e
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Pacex.Gen
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderApplication.Generic.3095451
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareApplication.Generic.3095451
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftApplication.Generic.3095451 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=71)
Antiy-AVLTrojan/Generic.ASBOL.C68D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataApplication.Generic.3095451
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4317495
BitDefenderThetaGen:NN.ZexaF.34114.InZ@aOKLpMd
ALYacApplication.Generic.3095451
VBA32Trojan.Packed
RisingTrojan.Kryptik!1.D238 (CLASSIC)
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_60%
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Application.Generic.3095451?

Application.Generic.3095451 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment