Malware

Exploit.Win32.Shellcode.wiq removal guide

Malware Removal

The Exploit.Win32.Shellcode.wiq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.wiq virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
tripsafe.fun

How to determine Exploit.Win32.Shellcode.wiq?


File Info:

crc32: 55C7F6D0
md5: 477aba0bf9d5c8692432bbac9b503002
name: 477ABA0BF9D5C8692432BBAC9B503002.mlw
sha1: 1de536c335521f6dadf22794ff224db3e0fbdcb9
sha256: da0863c8100f03955cdc4f964d9931c1921e46cc1b9318aebc88dff4cfad4906
sha512: ff1ff4414079129842a543438ca6ad2f70b0a2793084f3e9bcc6120f485a69ed190bcbdcb085a6fc8d1fa091c5139eae90b58116ebac0a97096a9d816637d4d4
ssdeep: 12288:PE8GMyL/ibOHzkn8Pv8fjUYeonwdGYpLDCCqFaK4WYoxXHe9BsE:AMIzHzkn884onMphuZ5ZHU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: deboot.exe
Product: 1.7.6
FileVersions: 1.0.5.4
LegalCo: Copyri (C) 2019, matric
Translation: 0x0419 0x011f

Exploit.Win32.Shellcode.wiq also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45092211
FireEyeGeneric.mg.477aba0bf9d5c869
Qihoo-360Win32/Trojan.PWS.d75
ALYacTrojan.Agent.Raccoon
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 00574f091 )
BitDefenderTrojan.GenericKD.45092211
K7GWTrojan ( 00574f091 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9814885-0
KasperskyExploit.Win32.Shellcode.wiq
AlibabaTrojan:Win32/Shellcode.0b3bbe37
Ad-AwareTrojan.GenericKD.45092211
EmsisoftTrojan.GenericKD.45092211 (B)
ComodoMalware@#3aez8liemnh08
F-SecureTrojan.TR/AD.StellarStealer.ylasb
DrWebTrojan.PWS.Siggen2.58526
TrendMicroTROJ_FRS.VSNW15L20
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.GenKD
AviraTR/AD.StellarStealer.ylasb
MAXmalware (ai score=88)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MS!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B00D73
ZoneAlarmExploit.Win32.Shellcode.wiq
GDataTrojan.GenericKD.45092211
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R359254
Acronissuspicious
McAfeeGenericRXAA-AA!477ABA0BF9D5
VBA32BScope.Trojan.Injuke
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIIT
TrendMicro-HouseCallTROJ_FRS.VSNW15L20
RisingTrojan.Kryptik!8.8 (TFE:5:FNh7hMIRqi)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GWXD!tr
BitDefenderThetaGen:NN.ZexaF.34700.FmGfa81Fpcp
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Exploit.Win32.Shellcode.wiq?

Exploit.Win32.Shellcode.wiq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment