Malware

Malware.AI.3006895221 removal instruction

Malware Removal

The Malware.AI.3006895221 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3006895221 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Malware.AI.3006895221?


File Info:

name: 296B516243E70A9568C2.mlw
path: /opt/CAPEv2/storage/binaries/678f8094f827cae342851505ec6f3200665714d8b66ac12a59c92d3a9d8dc6d4
crc32: BFA5AEDE
md5: 296b516243e70a9568c21b0f25136b1f
sha1: c6e067b709096dc1c479af5016d9e552224c0e93
sha256: 678f8094f827cae342851505ec6f3200665714d8b66ac12a59c92d3a9d8dc6d4
sha512: a27084b1c9d172bdcfcb72a345436fae8b973bfec46e99b2f4728253fb60cf9112523bf3b8524e9aabac30b5b44813b3b59e083a4b14b2c7af43c9b6ce615b42
ssdeep: 12288:CxgdxgKwkP2xgKwkPHxgSxgSxgAxgVxg:egfgKVPqgKVPRgOgOgUg3g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190B57F62310DBFCDE81C8E7049BAC64515A76DAF2810D5A2FB3CBFCA77B2D4A550421E
sha3_384: dcb21c6fd924a781c5c8cdd6f46e1c2c6010b10408da4042e7444a7aa9a432245cae4e0ea3cb2a0b5106148b5f465292
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-08-20 15:52:02

Version Info:

Translation: 0x0000 0x04b0
Comments: AIMWARE.net Loader
CompanyName: AIMWARE
FileDescription: v1go
FileVersion: 1.3.3.7
InternalName: v1go.exe
LegalCopyright: Copyright © AIMWARE 2016
LegalTrademarks:
OriginalFilename: v1go.exe
ProductName: v1go
ProductVersion: 1.3.3.7
Assembly Version: 1.3.3.7

Malware.AI.3006895221 also known as:

LionicHacktool.MSIL.FakeHack.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.612555
FireEyeGeneric.mg.296b516243e70a95
CAT-QuickHealTrojan.GenericFC.S6059784
McAfeeGenericRXGL-BK!296B516243E7
CylanceUnsafe
K7AntiVirusTrojan ( 00519afd1 )
BitDefenderThetaGen:NN.ZemsilF.34294.mo0@a8AdsOb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Hoax.FakeHack.ATL
TrendMicro-HouseCallTROJ_GEN.R002C0PKP21
ClamAVWin.Malware.Msilperseus-6848157-0
KasperskyHEUR:Hoax.MSIL.FakeHack.gen
BitDefenderGen:Variant.Bulz.612555
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10bae12a
Ad-AwareGen:Variant.Bulz.612555
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PKP21
McAfee-GW-EditionGenericRXGL-BK!296B516243E7
EmsisoftGen:Variant.Bulz.612555 (B)
IkarusPUA.MSIL.Hoax
GDataGen:Variant.Bulz.612555
MaxSecureTrojan.Malware.300983.susgen
AviraJOKE/FakeHack.zrglh
Antiy-AVLTrojan/Generic.ASMalwS.224258D
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.612555
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3006895221
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetRiskware/FakeHack
AVGWin32:Evo-gen [Susp]
PandaTrj/GdSda.A

How to remove Malware.AI.3006895221?

Malware.AI.3006895221 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment