Malware

Should I remove “Exploit.Win32.Shellcode.xph”?

Malware Removal

The Exploit.Win32.Shellcode.xph is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.xph virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Exploit.Win32.Shellcode.xph?


File Info:

crc32: 71A5E2EB
md5: afb2aa330b19c27d1b457beaa714185c
name: AFB2AA330B19C27D1B457BEAA714185C.mlw
sha1: 14739f3edd61320a0fba55f80eb7febc65d27de4
sha256: 44bf57aab1594dd8ce02e2020a2af2b5cf0a7f4c9093c937ad3597f90177140e
sha512: bf14c912c4aaf4f5fcbe9cbac2faef60a853f1aa97221b511f1f97e63226555afb6c86fc8fe13836d983b6cb44a38509cc37b4c5929fb72bddbfaac6672f5da0
ssdeep: 3072:lMn0Xr6MmMw+ULi2DLCzH0KlIIv4Vk3ALxf8WJfcj8RrNDFa6tPssPy:lWr+UG2DLCzH0K+IvV3C2AfK8Zos
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.9
FileVersions: 1.0.5.8
LegalCo: Copyri (C) 2019, permudationzy

Exploit.Win32.Shellcode.xph also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36013359
FireEyeGeneric.mg.afb2aa330b19c27d
ALYacTrojan.GenericKD.36013359
CylanceUnsafe
K7AntiVirusTrojan ( 00575ba11 )
AlibabaTrojan:Win32/Shellcode.59928094
K7GWTrojan ( 00575ba11 )
Cybereasonmalicious.30b19c
CyrenW32/Kryptik.CWC.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
CynetMalicious (score: 100)
KasperskyExploit.Win32.Shellcode.xph
BitDefenderTrojan.GenericKD.36013359
Paloaltogeneric.ml
Ad-AwareTrojan.GenericKD.36013359
SophosMal/Generic-S
F-SecureTrojan.TR/AD.SmokeLoader.oytep
DrWebTrojan.PWS.Siggen2.61003
TrendMicroTROJ_GEN.R011C0DA921
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
EmsisoftTrojan.GenericKD.36013359 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.36013359
JiangminExploit.ShellCode.bga
AviraTR/AD.SmokeLoader.oytep
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D225852F
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmExploit.Win32.Shellcode.xph
MicrosoftTrojan:Win32/Azorult.FW!MTB
AhnLab-V3Malware/Win32.RL_Generic.R362098
Acronissuspicious
McAfeeGenericRXAA-AA!AFB2AA330B19
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIPH
TrendMicro-HouseCallTROJ_GEN.R011C0DA921
TencentWin32.Exploit.Shellcode.Lrig
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.HGHW!tr
BitDefenderThetaGen:NN.ZexaF.34742.omGfaS1Jkfh
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Exploit.35c

How to remove Exploit.Win32.Shellcode.xph?

Exploit.Win32.Shellcode.xph removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment