Malware

Generic.Exploit.Shellcode.1.964779E3 removal guide

Malware Removal

The Generic.Exploit.Shellcode.1.964779E3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Exploit.Shellcode.1.964779E3 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Generic.Exploit.Shellcode.1.964779E3?


File Info:

name: BAAC1061E1454D5207B0.mlw
path: /opt/CAPEv2/storage/binaries/36cd2467986ea6362db8aece65842b3c86c8ffb5515cfea5038bd67e25839fa1
crc32: 9CC34BE9
md5: baac1061e1454d5207b0f144f8265f1d
sha1: 92a46bafabb52195e24abfe8961a5306fc1e1c63
sha256: 36cd2467986ea6362db8aece65842b3c86c8ffb5515cfea5038bd67e25839fa1
sha512: 2b91081320d13e752f1777b7cff8dc9dd79c8a65a408e1d17fd4c77f4d13b970c389c8d85d96ea65411f08d4f2ee1a28e7e232068a814edcab18cad0575da16e
ssdeep: 12288:uCtR/FW9KLii6uuE7YDX5CI1DoG7YIWmKdV0t:bTFWl5CI1NYIyX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B305F701BBA05024F9F726F986FE30689A3DB9E11718E0D752C42AED9625BF07C31B57
sha3_384: cae93b7dff8e5bdf8c4a4a359a5f662681c5c2d577d2cd09d2b4679a3c83a82b851c3bd70357d3fbecfbab71f0b4e840
ep_bytes: e9f73f0000e992830000e99dd40800e9
timestamp: 2021-11-28 09:02:53

Version Info:

0: [No Data]

Generic.Exploit.Shellcode.1.964779E3 also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanDeepScan:Generic.Exploit.Shellcode.1.964779E3
CyrenW32/Agent.DQW.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Rozena.PL
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Exploit.Shellcode.1.964779E3
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazpoUacthRvl9YPcynAjhsUn)
Ad-AwareDeepScan:Generic.Exploit.Shellcode.1.964779E3
FireEyeGeneric.mg.baac1061e1454d52
EmsisoftDeepScan:Generic.Exploit.Shellcode.1.964779E3 (B)
IkarusExploit.ShellCode
GDataDeepScan:Generic.Exploit.Shellcode.1.964779E3
MAXmalware (ai score=85)
ArcabitDeepScan:Generic.Exploit.Shellcode.1.964779E3
MicrosoftTrojan:Win32/Swrort.A
ALYacDeepScan:Generic.Exploit.Shellcode.1.964779E3
TencentTrojan.Win32.BitCoinMiner.la
SentinelOneStatic AI – Suspicious PE
FortinetW32/Rozena.AFO!tr
BitDefenderThetaGen:NN.ZexaF.34294.ZKW@au@aRAni
Cybereasonmalicious.1e1454
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.Exploit.Shellcode.1.964779E3?

Generic.Exploit.Shellcode.1.964779E3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment