Malware

Exploit.Win32.Shellcode.xfd removal guide

Malware Removal

The Exploit.Win32.Shellcode.xfd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.xfd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
trashbininspector.fun

How to determine Exploit.Win32.Shellcode.xfd?


File Info:

crc32: 04C62BED
md5: 414dfdffea7684caa9ea925b61d1cd6b
name: 414DFDFFEA7684CAA9EA925B61D1CD6B.mlw
sha1: a0b74a9c63e4a10e84e04381ae93d01d6dbfb05b
sha256: 962f73780df929deebef79caa97fe5432bf3163ad11abab65ad869827dd062a8
sha512: e822166b009390855bc01792ae6e891ef44aa07d2d8fea6871a4b1964ebcb9d0a80e7d17b245ddcede90cc7570812dc3b081f0b089036e3e22e70c4696fa5dd0
ssdeep: 12288:DDHwYQIhuC3bC9GPu4zKTDeOYvgNWr9sW5aqJKnCj:fHeC3bCsu4zeDeOYvcWqW5aVnCj
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationzi

Exploit.Win32.Shellcode.xfd also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.56849
MicroWorld-eScanTrojan.GenericKD.35915391
FireEyeGeneric.mg.414dfdffea7684ca
McAfeeGenericRXNE-RE!414DFDFFEA76
CylanceUnsafe
AegisLabHacktool.Win32.Shellcode.3!c
SangforMalware
K7AntiVirusTrojan ( 005756381 )
BitDefenderTrojan.GenericKD.35915391
K7GWTrojan ( 005756381 )
BitDefenderThetaGen:NN.ZexaF.34700.CmGfaGDet1nc
CyrenW32/Trojan.RVPE-3094
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HILR
TrendMicro-HouseCallTROJ_GEN.R002H0CLT20
AvastWin32:DropperX-gen [Drp]
KasperskyExploit.Win32.Shellcode.xfd
AlibabaExploit:Win32/Shellcode.c7e95abd
ViRobotTrojan.Win32.Z.Malpack.463872.A
TencentWin32.Exploit.Shellcode.Ozsf
Ad-AwareTrojan.GenericKD.35915391
SophosMal/Generic-S
ComodoMalware@#sz1mplzru1im
F-SecureTrojan.TR/Crypt.Agent.nbzep
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.nbzep
MAXmalware (ai score=99)
MicrosoftTrojan:Win32/Zenpack.MU!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D224067F
ZoneAlarmExploit.Win32.Shellcode.xfd
GDataTrojan.GenericKD.35915391
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Azorult
ALYacTrojan.Glupteba.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
APEXMalicious
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HGHW!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Exploit.ebd

How to remove Exploit.Win32.Shellcode.xfd?

Exploit.Win32.Shellcode.xfd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment