Malware

Exploit.ShellCode removal

Malware Removal

The Exploit.ShellCode is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.ShellCode virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Creates a hidden or system file
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
i.imgur.com

How to determine Exploit.ShellCode?


File Info:

crc32: 53283C9B
md5: a22713ab89c1db3dc814cb4f8adfedb4
name: A22713AB89C1DB3DC814CB4F8ADFEDB4.mlw
sha1: 19884afbf51d9e68330d8725348e74ad7081f815
sha256: 335eaabdf4e08e80d1f4c4904e77a800cb07f0820faab4012a565d8c0b23483b
sha512: 9d18faf49d9ef73c4d41fcae9d958fc0498723afc18f1d1bfa1da0c8c024c76e42f773cbb520ddcf81eff471bf917079e6282125aec81d0632696a4982912156
ssdeep: 24576:IzDeGxAt7hsUslrSRMalFK3nCG/XwHG5nO7p6wFpg/5DUcDDsPI:IoyNlSy5kkrKI
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Exploit.ShellCode also known as:

MicroWorld-eScanGen:Variant.Bulz.238237
Qihoo-360Win32/Trojan.Exploit.7ee
McAfeeArtemis!A22713AB89C1
MalwarebytesExploit.ShellCode
SangforMalware
K7AntiVirusTrojan ( 00573b491 )
BitDefenderGen:Variant.Bulz.238237
K7GWTrojan ( 00573b491 )
ArcabitTrojan.Bulz.D3A29D
CyrenW32/Trojan.PHON-4377
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.KW
Paloaltogeneric.ml
KasperskyHEUR:Exploit.Win32.Shellcode.gen
AlibabaTrojan:Win32/GenCBL.291c6f27
Ad-AwareGen:Variant.Bulz.238237
SophosMal/BadCert-Gen
Comodofls.noname@0
F-SecureTrojan.TR/Redcap.feyjn
DrWebTrojan.Siggen11.35175
TrendMicroTROJ_GEN.R002C0RKR20
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Bulz.238237
EmsisoftMalCert.A (A)
AviraTR/Redcap.feyjn
MAXmalware (ai score=81)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA33
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataWin32.Trojan.Agent.IZ6T4P
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.238237
VBA32Malware-Cryptor.Limpopo
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0RKR20
IkarusTrojan.Win32.Gencbl
FortinetW32/Rugmi.FAH!tr.dldr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Exploit.ShellCode?

Exploit.ShellCode removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment