Malware

Malware.AI.3060296263 removal instruction

Malware Removal

The Malware.AI.3060296263 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3060296263 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Malware.AI.3060296263?


File Info:

name: 0F05EAE314AF18732B10.mlw
path: /opt/CAPEv2/storage/binaries/c0481d1a1a580a08c6abdaa155ba157f07fb683c2b5c869b56f3be1995062133
crc32: 626C4019
md5: 0f05eae314af18732b10153e038e488f
sha1: a8497dcdf2b844873bb55866bdf442764bacd6be
sha256: c0481d1a1a580a08c6abdaa155ba157f07fb683c2b5c869b56f3be1995062133
sha512: 37d890cc2a22ecf8a52253f4ec9cd474db0b8dafa17b224de2d069e34569599ef8fc75fd0441b6179fbdaae660cdee941ae9baacdbfdfaff210b9bfb00bcef0c
ssdeep: 768:D3CVwjHJsK9bkr02SRDnWaaaw4CQbRzfMQvHcSwXkNkE95ZK0oZZkj2/:2VqHJsEb92gDWWVR7HvTzNkgFr2/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107335A42BA48CD12C17A5A7AC89EDE7003EDBC20AC63DA9B3DD53B5E25793D2140758F
sha3_384: 77a85f6d95377cab9baa92097a15a87614e88fc80cb2568bba0016f2e0bafa2bce3bdb698ce7c26190edf576408c18b3
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-05-10 20:30:19

Version Info:

Translation: 0x0000 0x04b0
FileDescription: java
FileVersion: 1.0.0.0
InternalName: java.exe
LegalCopyright: Copyright © 2018
OriginalFilename: java.exe
ProductName: java
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3060296263 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.202045
FireEyeGeneric.mg.0f05eae314af1873
ALYacGen:Variant.Ursu.202045
K7AntiVirusTrojan ( 004bf1141 )
BitDefenderGen:Variant.Ursu.202045
K7GWTrojan ( 004bf1141 )
Cybereasonmalicious.314af1
BitDefenderThetaGen:NN.ZemsilF.34062.dm1@a0xSCvf
ESET-NOD32a variant of MSIL/Kryptik.OCX
ClamAVWin.Malware.Zusy-6866357-0
KasperskyHEUR:Backdoor.MSIL.Generic
Ad-AwareGen:Variant.Ursu.202045
EmsisoftGen:Variant.Ursu.202045 (B)
DrWebBackDoor.Bladabindi.1705
APEXMalicious
JiangminBackdoor.MSIL.fgji
AviraHEUR/AGEN.1107944
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.2613B5E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Ursu.202045
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.ZBot.C661250
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3060296263
IkarusTrojan.MSIL.MultiPacked
PandaTrj/GdSda.A
YandexTrojan.GenKryptik!f4TKPcmMurw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3060296263?

Malware.AI.3060296263 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment