Malware

What is “Exploit.Win32.Shellcode.aaxe”?

Malware Removal

The Exploit.Win32.Shellcode.aaxe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.aaxe virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Exploit.Win32.Shellcode.aaxe?


File Info:

crc32: 174BF884
md5: 193632c5516bdc656fd95f85fcab4392
name: 193632C5516BDC656FD95F85FCAB4392.mlw
sha1: 06ff26b77b801cb487367d807be5033ecc724d34
sha256: 575fadc1850594983be11811f89e72e61d2911415ddec1e0ae26615da823e912
sha512: 09ea48413dc8f88bac5ea4fe26798c93365a14d6d536a381fab8c6eb1cd8a0001af8480c34b5454ee02eb963adc0a8c9005b0c12eecb7869fdcf95226eb878bf
ssdeep: 12288:UhGMv004ITIHQMPuPMXpi57YInqdgU5KGYNKIlsesOyvxg4:UhfWHViMY57Y/dgDpkIlsVOWxR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calimatimodunadop.exe
FileVersions: 7.0.2.54
LegalCopyrights: Vsekdar
ProductVersions: 7.0.21.45
Translation: 0x0129 0x04f4

Exploit.Win32.Shellcode.aaxe also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.40699
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.45903095
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Shellcode.5da0d8d5
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Kryptik.DPT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HJYL
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Malware.Bulz-9842209-0
KasperskyExploit.Win32.Shellcode.aaxe
BitDefenderTrojan.GenericKD.45903095
MicroWorld-eScanTrojan.GenericKD.45903095
TencentWin32.Exploit.Shellcode.Dxna
Ad-AwareTrojan.GenericKD.45903095
SophosML/PE-A
ComodoMalware@#22hoiu8ueqp45
BitDefenderThetaGen:NN.ZexaF.34628.Jq0@ayPkjCaG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DCJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.193632c5516bdc65
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.degi
AviraTR/AD.StellarStealer.atf
eGambitUnsafe.AI_Score_79%
KingsoftWin32.Exploit.Shellcode.aa.(kcloud)
MicrosoftTrojan:Win32/Azorult.NE!MTB
ArcabitTrojan.Generic.D2BC6CF7
AegisLabTrojan.Multi.Generic.4!c
GDataWin32.Trojan.PSE.18AAYXX
AhnLab-V3Adware/Win.Lollipop.R372762
Acronissuspicious
McAfeeRDN/RaccoonStealer
MAXmalware (ai score=86)
VBA32Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DCJ21
RisingTrojan.Azorult!8.107E7 (CLOUD)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:BotX-gen [Trj]
Qihoo-360Win32/TrojanSpy.Generic.HwoC7fsA

How to remove Exploit.Win32.Shellcode.aaxe?

Exploit.Win32.Shellcode.aaxe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment