Adware

Adware.Generic.3006116 (file analysis)

Malware Removal

The Adware.Generic.3006116 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Generic.3006116 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Adware.Generic.3006116?


File Info:

name: DB989A293604D3766F51.mlw
path: /opt/CAPEv2/storage/binaries/1e24877576f4b74e745f183e81bbb51c0e636d82451cb914b3faf6c152bcc03b
crc32: 3BF0E9B4
md5: db989a293604d3766f510fcad386fb31
sha1: 20a3b97e96e1866474683c3217901149362f5176
sha256: 1e24877576f4b74e745f183e81bbb51c0e636d82451cb914b3faf6c152bcc03b
sha512: 3b4c84effa91a3e15ca1e54d2ee8835af3bd3c59a5e3339f8c81ebeabdc3e8022c86fa11333cf77ce37048b40975bd830d68ba8b4a1acfaa4d1837a66ac7d53d
ssdeep: 98304:YVrNnD2MAyoI73vcSBJrhofyMH7cha8UXEqFimzJIy:YVrUMAycSIygAa3+mmy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5363342A1ACB7D3D5C36A38361414A1DF928339611DB6CBD6F582A42736F7F29C1273
sha3_384: 45dead7317f1f7449dc79d2121c02bf8139e693f7d6f26e19dc06e68acf3cbe201dc2f265ef6017b416178a1d4d7885b
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

FileDescription: Producer shd
FileVersion:
LegalCopyright: (C)
ProductName:
Translation: 0x0804 0x04e4

Adware.Generic.3006116 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Generic.3006116
FireEyeAdware.Generic.3006116
ALYacAdware.Generic.3006116
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanDropper:Win32/Ramnit.86f7c3cf
K7GWTrojan ( 0050b64b1 )
K7AntiVirusTrojan ( 0050b64b1 )
ArcabitAdware.Generic.D2DDEA4
CyrenW32/Dropper.DS.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
APEXMalicious
ClamAVWin.Trojan.Ramnit-9753960-0
BitDefenderAdware.Generic.3006116
NANO-AntivirusTrojan.Win32.RDN.eikobp
AvastWin32:Adware-gen [Adw]
Ad-AwareAdware.Generic.3006116
SophosMal/Agent-AUG
ComodoTrojWare.Win32.Injector.KRTE@57zc23
F-SecureTrojan.TR/Drop.Agent.mobnd
DrWebAdware.Searcher.1222
ZillyaDropper.Agent.Win32.430081
TrendMicroTROJ_GEN.R002C0RDJ22
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
EmsisoftAdware.Dropper (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Drop.Agent.mobnd
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ViRobotTrojan.Win32.Z.Agent.4931298
GDataAdware.Generic.3006116
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!DB989A293604
MAXmalware (ai score=65)
VBA32Adware.Searcher
MalwarebytesTrojan.ChinAd
TrendMicro-HouseCallTROJ_GEN.R002C0RDJ22
IkarusWin32.Ramnit
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.e96e18

How to remove Adware.Generic.3006116?

Adware.Generic.3006116 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment