Adware

Adware.Generic.3006760 (file analysis)

Malware Removal

The Adware.Generic.3006760 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Generic.3006760 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

How to determine Adware.Generic.3006760?


File Info:

name: F07A066EA16739728090.mlw
path: /opt/CAPEv2/storage/binaries/e72afaf4d09c20a156ff195bfd5e3cc27f94a151fc3a03251243dad4824c8843
crc32: 7725B86C
md5: f07a066ea16739728090c4943370f8ce
sha1: 01d6fd7a9144d3f06d4a86eb2001e54cb6f2b493
sha256: e72afaf4d09c20a156ff195bfd5e3cc27f94a151fc3a03251243dad4824c8843
sha512: b611a96924a335e548182fc878917e83fbc0acdf85c8d2eb048007d098efbb98c6fe71d1f3968e6421ca69ab5e062f015aff780eec841d39864da05c05ba5e7e
ssdeep: 24576:SZhNrRCfPyZhNrRCfPaZhNrRCfPyZhNrRCfP:SZpCfKZpCfSZpCfKZpCf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CE57D2BF6D08433D223167C9C9B97A99D2ABE502E2954463FF91D8C4F3D78138262D7
sha3_384: cac1982e2e1f216762dabc948daa7cfbd76e62f6e67407bb830be5caeb2487ac40e570bb3056dfff0766f5b2f08d95f6
ep_bytes: 558bec83c4f033c08945f0b8389b4500
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Adware.Generic.3006760 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Generic.3006760
FireEyeGeneric.mg.f07a066ea1673972
CAT-QuickHealTrojan.Generic.27193
McAfeeW32/Fasong.worm
CylanceUnsafe
K7AntiVirusTrojan ( 0000ca6e1 )
K7GWTrojan ( 0000ca6e1 )
Cybereasonmalicious.ea1673
ArcabitAdware.Generic.D2DE128
BaiduWin32.Trojan-PSW.OLGames.bm
CyrenW32/Worm.TXBC-8767
ESET-NOD32Win32/Fasong.C
APEXMalicious
ClamAVWin.Malware.Fasong-9910797-0
KasperskyWorm.Win32.Fasong.c
BitDefenderAdware.Generic.3006760
NANO-AntivirusTrojan.Win32.Fasong.cfoac
AvastWin32:CrypterX-gen [Trj]
RisingWorm.Fasong!1.D14C (CLASSIC)
Ad-AwareAdware.Generic.3006760
EmsisoftAdware.Generic.3006760 (B)
ComodoWorm.Win32.Fasong.C@1nqv
DrWebWin32.HLLW.Fasong.2
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroWORM_FASONG.C
McAfee-GW-EditionBehavesLike.Win32.Fasong.wt
SophosML/PE-A + Troj/Fasong-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/WebPass.01
eGambitUnsafe.AI_Score_99%
AviraADWARE/Adware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.88B5C
KingsoftHeur.SSC.2800857.1216.(kcloud)
MicrosoftWorm:Win32/Fasong.C
ViRobotWorm.Win32.A.Fasong.182372
GDataAdware.Generic.3006760
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Fasong.R192909
Acronissuspicious
BitDefenderThetaAI:Packer.106356D321
ALYacAdware.Generic.3006760
MAXmalware (ai score=62)
VBA32Worm.Fasong
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallWORM_FASONG.C
TencentTrojan.Win32.BitCoinMiner.la
IkarusWorm.Win32.Fasong
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Fasong.FEE7!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Adware.Generic.3006760?

Adware.Generic.3006760 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment