Malware

Should I remove “Exploit.Win32.Shellcode.mzn”?

Malware Removal

The Exploit.Win32.Shellcode.mzn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.mzn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Exploit.Win32.Shellcode.mzn?


File Info:

name: 0AD8B7683B97D76342D3.mlw
path: /opt/CAPEv2/storage/binaries/4afb65ea2f85940356635209d2ba4501496da301a7337bf853c4b403d64c99b2
crc32: 5B2E987B
md5: 0ad8b7683b97d76342d3705dbd99f339
sha1: 860661ef1f5384bead298917018dbe3e83f39e6d
sha256: 4afb65ea2f85940356635209d2ba4501496da301a7337bf853c4b403d64c99b2
sha512: 47548f49298fd0ef4e4994d3afbdbc3f1b1649fe57ce958aef1c949433501c755a71f5a53cfed70e29e1e6c5d5a2caffbb1252bc48c824398914cc9016e6992c
ssdeep: 6144:fKG4OFgEit0jjjjMrMrMvw61o+tyCynPkkmQB9RwzDBf3cLq5vqyW/7e4Z44BJHi:SKk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D734A603E60A269DC0C588B780B9C85145C95FA851B8D49BBF70360F5AFF0DB69AEF47
sha3_384: 3581fb387dcf49a76166cf5b259451f864aa7689b8e5e07c4255b4d534610026d45a56d3900d9e4a7f08d9af4a2bcaaa
ep_bytes: e87a040000e936fdffff558bec81ec28
timestamp: 2016-04-02 13:59:58

Version Info:

FileDescription: 光速鼠标连点器 官方网址 www.baidu-home.com
FileVersion: 4, 0, 0, 5
InternalName: 光速鼠标连点器.exe
LegalCopyright: Copyright (C) 2013
OriginalFilename: 光速鼠标连点器.exe
ProductName: 光速鼠标连点器
ProductVersion: 4, 0, 0, 5
Translation: 0x0804 0x04b0

Exploit.Win32.Shellcode.mzn also known as:

LionicTrojan.Win32.Shellcode.3!c
CAT-QuickHealTrojan.Shellcode
SkyhighBehavesLike.Win32.Dropper.dm
McAfeeArtemis!0AD8B7683B97
MalwarebytesGeneric.Malware/Suspicious
ZillyaExploit.ShellCode.Win32.959
SangforExploit.Win32.Shellcode.Vtqy
AlibabaExploit:Win32/Shellcode.f6430cdd
Cybereasonmalicious.f1f538
SymantecW32.Priter
APEXMalicious
CynetMalicious (score: 100)
KasperskyExploit.Win32.Shellcode.mzn
TencentMalware.Win32.Gencirc.10bdb21f
F-SecureTrojan.TR/Redcap.ykjrz
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.0ad8b7683b97d763
SophosMal/Generic-S
AviraTR/Redcap.ykjrz
Antiy-AVLTrojan/Win32.PossibleThreat
KingsoftWin32.Exploit.Shellcode.mzn
MicrosoftTrojan:Win32/Malgent!MSR
ZoneAlarmExploit.Win32.Shellcode.mzn
GDataWin32.Trojan.Agent.LAQO13
VBA32BScope.Trojan.Ekstak
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CBG24
RisingTrojan.Generic@AI.89 (RDML:fiyiYfdi+mg1IfXNpCk05Q)
MaxSecureTrojan.Malware.233033810.susgen
DeepInstinctMALICIOUS

How to remove Exploit.Win32.Shellcode.mzn?

Exploit.Win32.Shellcode.mzn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment