Malware

Exploit.Win32.Shellcode.nya information

Malware Removal

The Exploit.Win32.Shellcode.nya is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.nya virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Sindhi
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
brf1.secondaryservicelog.cloudns.cx
a.tomx.xyz

How to determine Exploit.Win32.Shellcode.nya?


File Info:

crc32: D3C6804C
md5: 87e2aeeafa8f331d09fad9121b8d0de6
name: helpchma_1.exe
sha1: 514bae2f2802db837171e6d3c87336eabd287222
sha256: bb2e69527e99fde41ed1b3b368308d79e837062a15af538fd41e87f387136651
sha512: 27b28229a43f6997bf1fb7dc302fbeaf959f56a974f3e3435b2bd6d356c74731290dae3012cf7077278db395b4fdb3eec6c54fde83fc6663b08ec3f4fc23ab9c
ssdeep: 3072:8hczeT5y4Vvr5u1aYb0l05fpLX5gEkFhf446irbyMOUbWRswrGqYd:8hczeT5y4Zr5u1Jw0vxG6i6M1S+F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Exploit.Win32.Shellcode.nya also known as:

MicroWorld-eScanGen:Variant.Midie.70514
McAfeeGenericRXJP-XQ!87E2AEEAFA8F
CylanceUnsafe
AegisLabHacktool.Win32.Shellcode.3!c
SangforMalware
BitDefenderGen:Variant.Midie.70514
K7GWTrojan ( 0056088c1 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Midie.70514
KasperskyExploit.Win32.Shellcode.nya
AlibabaExploit:Win32/Shellcode.9dce20ec
NANO-AntivirusTrojan.Win32.Kryptik.hatlcj
ViRobotTrojan.Win32.Z.Midie.197120
TencentWin32.Exploit.Shellcode.Ednu
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/AD.MortyStealer.jwrbl
DrWebTrojan.PWS.Siggen2.43523
TrendMicroTROJ_GEN.R002C0WBE20
McAfee-GW-EditionBehavesLike.Win32.ZeroAccess.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.87e2aeeafa8f331d
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.CBOX-8147
JiangminExploit.ShellCode.vk
AviraTR/AD.MortyStealer.jwrbl
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Midie.D11372
ZoneAlarmExploit.Win32.Shellcode.nya
AhnLab-V3Trojan/Win32.MalPe.R325901
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34090.mSW@aunPexeG
ALYacGen:Variant.Midie.70514
MAXmalware (ai score=85)
MalwarebytesSpyware.AzorUlt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBBY
TrendMicro-HouseCallTROJ_GEN.R002C0WBE20
RisingExploit.Shellcode!8.2A (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HBCF!tr
Ad-AwareGen:Variant.Midie.70514
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f2802d
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Exploit.193

How to remove Exploit.Win32.Shellcode.nya?

Exploit.Win32.Shellcode.nya removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment