Malware

Generic.Exploit.Shellcode.1.CEB6A59B removal guide

Malware Removal

The Generic.Exploit.Shellcode.1.CEB6A59B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Exploit.Shellcode.1.CEB6A59B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Executable displays a decoy image
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Generic.Exploit.Shellcode.1.CEB6A59B?


File Info:

name: 22111ABB7F821930E918.mlw
path: /opt/CAPEv2/storage/binaries/4130be01336511b85c74a4dd346e97bb9f13fefe7b0bf4bbf3ba9f004332cf13
crc32: F8F461E2
md5: 22111abb7f821930e9181e01f3e780a8
sha1: 3120c27aeeb63b8552b384fe0d8ad1acbf006dcc
sha256: 4130be01336511b85c74a4dd346e97bb9f13fefe7b0bf4bbf3ba9f004332cf13
sha512: fe7dbff73de7af3514324d92d7c6c67ad95f047a0135537b7d38cda5d93d6c9255948a6cd2bf0b9a1e1e40ad2c49bc7633182535c09c3540ee0ae6127336d15a
ssdeep: 49152:Bk+g3Z7PJoku6Tmr/cq+CZyzb35ujL8b1Qdr:Bk+kx6kJ4EqoKF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBA59E52F8EBA0F2EA075531489BE2AF2731B6155B32CEC7C540AE5AEC735E10D33526
sha3_384: ae80cddb4460e7329fde8ed70ce0d7dcfa3416db6ce7e72059dd847c64bcfc8a6bf47f8d0a3a841afffbe151de34fe43
ep_bytes: e93bddffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Generic.Exploit.Shellcode.1.CEB6A59B also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Exploit.Shellcode.1.CEB6A59B
FireEyeGeneric.mg.22111abb7f821930
CylanceUnsafe
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Exploit.Shellcode.1.CEB6A59B
Ad-AwareDeepScan:Generic.Exploit.Shellcode.1.CEB6A59B
EmsisoftDeepScan:Generic.Exploit.Shellcode.1.CEB6A59B (B)
SophosATK/Cobalt-EW
GDataDeepScan:Generic.Exploit.Shellcode.1.CEB6A59B
CynetMalicious (score: 100)
VBA32BScope.Trojan-Spy.Zbot
ALYacDeepScan:Generic.Exploit.Shellcode.1.CEB6A59B
MAXmalware (ai score=80)
MalwarebytesRansom.FileCryptor
RisingBackdoor.CobaltStrike!1.D9A1 (CLASSIC)
IkarusTrojan-Dropper.WinGo.Agent
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.b7f821

How to remove Generic.Exploit.Shellcode.1.CEB6A59B?

Generic.Exploit.Shellcode.1.CEB6A59B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment