Malware

Exploit.ShellCode.Gen removal instruction

Malware Removal

The Exploit.ShellCode.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.ShellCode.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Exploit.ShellCode.Gen?


File Info:

name: 378455A8A4948D778F6D.mlw
path: /opt/CAPEv2/storage/binaries/202ece49a3b4d4e5bdc6e532aa5bef06e4ed0db751f0cea814ae2e392d73b754
crc32: A4C839F8
md5: 378455a8a4948d778f6dd6bc1e02eaad
sha1: a942fd1fecc8c2f50cc49b281f7a04190eabe61c
sha256: 202ece49a3b4d4e5bdc6e532aa5bef06e4ed0db751f0cea814ae2e392d73b754
sha512: 76e0a1ae584bc47b2312a3ec2a48cc47772dcde8e402340a99bd33a37f0d5d97f759fed82d8ba8779e892a3a42cc3bcce08c1a8a34fb012dce419909c8c613cb
ssdeep: 6144:dJrfB3+pGsteKOqLVJ5bbZXegqw48gyH0YtnbvK/kFZj:dJrp3xssPWJtbZU8JFtrymB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5341321AC184E99F9A7673150734F87632EAD82AC32E72DC550FCD67E77361B863806
sha3_384: d73d4197a8c556c7b14cc6aea8042c2043f116955dd4788877b4532b4c1682377775a54f0a46f4b2d5c8a198dba10c4d
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2010-08-26 07:43:27

Version Info:

CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 3, 0, 0, 0
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2009 QVOD
OriginalFilename: QvodInstall.exe
ProductName: QvodInstall Module
ProductVersion: 3, 0, 0, 0
Translation: 0x0409 0x04b0

Exploit.ShellCode.Gen also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Win32.QVod.A
FireEyeGeneric.mg.378455a8a4948d77
CAT-QuickHealExploit.ShellCode.Gen
ALYacGen:Win32.QVod.A
CylanceUnsafe
VIPREWorm.Win32.Qvod.ank (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusBackdoor ( 00563cbc1 )
BitDefenderGen:Win32.QVod.A
K7GWBackdoor ( 00563cbc1 )
Cybereasonmalicious.8a4948
BitDefenderThetaGen:NN.ZexaF.34160.pK1ba4pcrohb
VirITWin32.QVod.I
CyrenW32/S-4cc62c0c!Eldorado
SymantecW32.Wapomi!gen1
ESET-NOD32Win32/Wapomi.K
BaiduWin32.Trojan.KillAV.c
TrendMicro-HouseCallPE_FUJACKS.EG-O
ClamAVWin.Trojan.Agent-1253176
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Crypted.dnmbw
ViRobotTrojan.Win32.A.KillAV.243200.A
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazpop4MZGPB3fm3FvU0TWY0L)
Ad-AwareGen:Win32.QVod.A
SophosML/PE-A + Mal/Mdrop-Y
DrWebTrojan.AVKill.10705
ZillyaTrojan.KillAV.Win32.4181
TrendMicroPE_FUJACKS.EG-O
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftGen:Win32.QVod.A (B)
APEXMalicious
GDataGen:Win32.QVod.A
JiangminTrojan/Generic.arob
Webroot
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASCommon.4
SUPERAntiSpywareTrojan.Agent/Gen-Anomaly
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Agent.243200.AB
Acronissuspicious
McAfeeGenericRXAA-FA!378455A8A494
MAXmalware (ai score=89)
VBA32Trojan.AVKill
MalwarebytesTrojan.Dropper
IkarusTrojan-Dropper.Win32.Small
PandaTrj/Genetic.gen
TencentTrojan.TenThief.QQPsw.uwp
YandexTrojan.GenAsa!7dplsGcWCrI
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Qvod.A
FortinetW32/Qvod.C!tr.pws
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Exploit.ShellCode.Gen?

Exploit.ShellCode.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment