Malware

Exploit.RpcDcom removal tips

Malware Removal

The Exploit.RpcDcom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.RpcDcom virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Exploit.RpcDcom?


File Info:

name: 455B7C56079C0CABFCF9.mlw
path: /opt/CAPEv2/storage/binaries/117c73c1e870640229e0ed4aab983654921ffb83789e69693dedfae7bcfc6563
crc32: 4EFF83B5
md5: 455b7c56079c0cabfcf9f82361d52f9d
sha1: 09eff70e2b9ab2e5b34507222934c6dca7cd4443
sha256: 117c73c1e870640229e0ed4aab983654921ffb83789e69693dedfae7bcfc6563
sha512: 017f0027098eeb8c00930c379497193aacd484cb8c9d9071e4e4eb46e6e89ee2d0cf8df9a23080c2d65b0a3dbac213cb78376e904c85f539063bb46bf2d6bc77
ssdeep: 49152:cpph7GBfWZ2pph7GBfW4HsDkYOMwwnMb4PmyVW/4MnYYJ2ZhqSGLHkJEMt:i77GBfWZE77GBfWYYOXwnS4rVTIDQt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4D54911B7E79136EDB32630197952305A37BD615B39C6CF52886A1E2FB2AC09E30773
sha3_384: 61d64d5442bd655a1061b10f7ed566fcc9105fc079a42c010301cf3c42dae8bb16f0c36dbd2dc1b5820848c567e7a0c5
ep_bytes: 6a606878110001e89b0e0000bf940000
timestamp: 2001-08-17 20:50:29

Version Info:

CompanyName: Microsoft Corporation
FileDescription: SAPISVR 5
FileVersion: 5.1.4111.00 (XPClient.010817-1148)
InternalName: SAPISVR5
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SAPISVR5
ProductName: Microsoft® Windows(TM) Operating System
ProductVersion: 5.1.4111.00
Translation: 0x0409 0x04b0

Exploit.RpcDcom also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Small.mCgp
tehtrisGeneric.Malware
DrWebTrojan.Siggen5.28081
MicroWorld-eScanTrojan.Generic.11103039
FireEyeGeneric.mg.455b7c56079c0cab
McAfeeGeneric-FANE!455B7C56079C
MalwarebytesSality.Virus.FileInfector.DDS
VIPRETrojan.Generic.11103039
SangforARMADILLO17
Cybereasonmalicious.6079c0
BitDefenderThetaGen:NN.ZexaE.34592.No3@aqtZ6Bgi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Futu.A
APEXMalicious
ClamAVWin.Malware.Kolabc-6736261-0
KasperskyVirus.Win32.Lamer.kp
BitDefenderTrojan.Generic.11103039
NANO-AntivirusTrojan.Win32.TrjGen.fanttn
AvastWin32:Evo-gen [Susp]
TencentVirus.Win32.Kolabc.aac
Ad-AwareTrojan.Generic.11103039
EmsisoftTrojan.Generic.11103039 (B)
ComodoMalware@#2y110rge8vbi
BaiduWin32.Worm.Agent.u
TrendMicroPE_FUTU.A
McAfee-GW-EditionBehavesLike.Win32.Trojan.vh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Siggen.qzol
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Ditertag.A
ArcabitTrojan.Generic.DA96B3F
GDataWin32.Trojan-Dropper.Rbot.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Facelabc.Gen
Acronissuspicious
VBA32Exploit.RpcDcom
ALYacTrojan.Generic.11103039
TrendMicro-HouseCallPE_FUTU.A
RisingSpyware.Zbot!1.648A (CLASSIC)
YandexWorm.Agent!ZZCQTfVQq3M
IkarusTrojan.Siggen
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Cerbu.ABAH!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Exploit.RpcDcom?

Exploit.RpcDcom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment