Malware

Exploit:Win32/ShellCode!mclg information

Malware Removal

The Exploit:Win32/ShellCode!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:Win32/ShellCode!mclg virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Exploit:Win32/ShellCode!mclg?


File Info:

name: F8391705CEC10E57E55A.mlw
path: /opt/CAPEv2/storage/binaries/2a75d7da2d616dacab45d624b7fb519f55d2acde237ecb83869d1b260b718a6a
crc32: 831316C3
md5: f8391705cec10e57e55a1cc319b848b2
sha1: 2f6ec65cc3fb2d394df710727786d4614d8ba6c6
sha256: 2a75d7da2d616dacab45d624b7fb519f55d2acde237ecb83869d1b260b718a6a
sha512: 59a6718b9219302b4823d100a90ce22d17c68018aa912ada17c516460ba221a5383a0cf924cc477c08af55667af67d572d32faff43cae875d73296b0d1c2b05d
ssdeep: 6144:RwhG1IYX8tI8Ty01GRJcD8LP1Gck4puaUJd0I:eEKXLnG31l4Jdh
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T11734F954F642FEB6E48A87FE14E2225682DEA680EB1DF6372950FD68014FB6C0373D45
sha3_384: cf1291af17591992b1974d16fd7771300c01368afc56db724efbea74553ed630f4c9ae2ae5389856b3dc776a1149def5
ep_bytes: 83ec1cc7057053f861000000008b5424
timestamp: 2019-01-08 20:51:04

Version Info:

0: [No Data]

Exploit:Win32/ShellCode!mclg also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shellcode.3!c
MicroWorld-eScanGen:Variant.Ursu.582578
SkyhighRDN/Generic Exploit
ALYacGen:Variant.Ursu.582578
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.2715578
SangforExploit.Win32.Shellcode.Vpz1
K7AntiVirusTrojan ( 0055eb191 )
AlibabaExploit:Win32/Shellcode.f33e3fd3
K7GWTrojan ( 0055eb191 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ursu.D8E3B2
BitDefenderThetaGen:NN.ZedlaF.36680.o86@a8yWiLg
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HABO
CynetMalicious (score: 100)
KasperskyExploit.Win32.Shellcode.lv
BitDefenderGen:Variant.Ursu.582578
NANO-AntivirusExploit.Win32.Shellcode.grkctg
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13bd405b
EmsisoftGen:Variant.Ursu.582578 (B)
F-SecureTrojan.TR/Crypt.Agent.qymoi
VIPREGen:Variant.Ursu.582578
TrendMicroHackTool.Win32.ShellCode.AA
SophosMal/Generic-S
JiangminExploit.ShellCode.ak
WebrootW32.Trojan.Gen
VaristW32/ABRisk.TQJZ-9058
AviraTR/Crypt.Agent.qymoi
MicrosoftExploit:Win32/ShellCode!mclg
ZoneAlarmExploit.Win32.Shellcode.lv
GDataGen:Variant.Ursu.582578
GoogleDetected
McAfeeRDN/Generic Exploit
TACHYONTrojan-Exploit/W32.Shellcode.238869
VBA32BScope.Exploit.Shellcode
MalwarebytesGeneric.Crypt.Trojan.DDS
PandaExploit/Shellcode.Behaviour
TrendMicro-HouseCallHackTool.Win32.ShellCode.AA
RisingExploit.Shellcode!8.2A (CLOUD)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.74125145.susgen
FortinetW32/Shellcode.LV!exploit
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Exploit:Win32/ShellCode!mclg?

Exploit:Win32/ShellCode!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment