Malware

Exploit.Win32.Shellcode.xdq removal tips

Malware Removal

The Exploit.Win32.Shellcode.xdq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.xdq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
apps.identrust.com
trashbininspector.fun

How to determine Exploit.Win32.Shellcode.xdq?


File Info:

crc32: 26DA143A
md5: 7fc16f01da38a340be2ebea016aeb3ff
name: 7FC16F01DA38A340BE2EBEA016AEB3FF.mlw
sha1: ec70a27f105436facef71c64c6e2f041b4f0bd14
sha256: 2495623296a5cea8686668a0b0ce1a9a1f7cadc639b36fc634933ebf7ba0c01a
sha512: e5758454820886f24fbc4da5e9912c8fd6165c424e5822010dbe2b3e9d77f162d001e252c3a5e85b41f683d44a13d9c6c6be516888c1f48ad5b0ff4382efdcf5
ssdeep: 12288:DLqFH7MGRT533thypgNfZB/Spc5bkCvqfLv3VNkdmk:38H7dRT533iEfZBKe2CWLNNkdj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationz

Exploit.Win32.Shellcode.xdq also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.58526
MicroWorld-eScanTrojan.GenericKD.45221821
FireEyeGeneric.mg.7fc16f01da38a340
McAfeeRDN/Generic.hbg
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005756051 )
BitDefenderTrojan.GenericKD.45221821
K7GWTrojan ( 005756051 )
BitDefenderThetaGen:NN.ZexaF.34700.DmGfaGKPzDlc
CyrenW32/Kryptik.CVF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyExploit.Win32.Shellcode.xdq
AlibabaTrojan:Win32/Shellcode.e42d9b49
ViRobotTrojan.Win32.Z.Agent.480768.BX
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
Ad-AwareTrojan.GenericKD.45221821
SophosML/PE-A
ComodoMalware@#auf7mijcz9k
F-SecureTrojan.TR/AD.StellarStealer.jqerd
McAfee-GW-EditionBehavesLike.Win32.Trojan.gc
EmsisoftTrojan.GenericKD.45221821 (B)
IkarusTrojan.Win32.Krypt
JiangminExploit.ShellCode.beh
AviraTR/AD.StellarStealer.jqerd
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MT!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B207BD
ZoneAlarmExploit.Win32.Shellcode.xdq
GDataTrojan.GenericKD.45221821
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Agent
ALYacTrojan.Agent.Raccoon
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILR
TencentWin32.Exploit.Shellcode.Amwf
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_85%
FortinetW32/Kryptik.HGHW!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.3B9F.Malware.Gen

How to remove Exploit.Win32.Shellcode.xdq?

Exploit.Win32.Shellcode.xdq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment