Malware

How to remove “Generic.Exploit.Shellcode.3.2FD1F607”?

Malware Removal

The Generic.Exploit.Shellcode.3.2FD1F607 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Exploit.Shellcode.3.2FD1F607 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Generic.Exploit.Shellcode.3.2FD1F607?


File Info:

name: 4997410F78E6BEC7AF09.mlw
path: /opt/CAPEv2/storage/binaries/2743d8b123762a3969abc9b0d461a10e2d965c3fd1b86c89a09b1f29c67c1803
crc32: 4848E769
md5: 4997410f78e6bec7af09481bc0ff96fc
sha1: 78f5f318691486bb3385293811b8190b0975e240
sha256: 2743d8b123762a3969abc9b0d461a10e2d965c3fd1b86c89a09b1f29c67c1803
sha512: 42e61c22654e817faec0a25fe74c215ac8b0992389d6f4212a5e259ea43803b573e1d1411c856fc9a0dfcda33791afc51434b0b5212d1267a65e84d239da6862
ssdeep: 768:ItZ7B/xr8H8zKsEuuFOw+hQgAFCYHn3xmS3glJz1YhNKNepZgqE7q3:ItBxF8czDEuuAlQgAHHISwlJWhN2Keqn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D23F11B27FA2D18F5F6F5B1652153B6AAE1BC114A766B5C0AF320153C71A032F52B23
sha3_384: ee4d3746b10c9046e69d9af3c082b75ffb6eec228b5e55b0ae1f1d6fd90c9d9ff3833caa0fcd36bec8a712e775b9e133
ep_bytes: 60be00d040008dbe0040ffff5783cdff
timestamp: 2009-04-04 23:58:52

Version Info:

Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName: Apache Software Foundation
FileDescription: ApacheBench command line utility
FileVersion: 2.2.14
InternalName: ab.exe
LegalCopyright: Copyright 2009 The Apache Software Foundation.
OriginalFilename: ab.exe
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
Translation: 0x0409 0x04b0

Generic.Exploit.Shellcode.3.2FD1F607 also known as:

Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Swrort.A
McAfeeGenericRXAA-AA!4997410F78E6
CylanceUnsafe
K7AntiVirusTrojan ( 001172b51 )
K7GWTrojan ( 001172b51 )
Cybereasonmalicious.f78e6b
CyrenW32/Swrort.B.gen!Eldorado
SymantecPacked.Generic.347
ESET-NOD32a variant of Win32/Rozena.BJG
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.MSShellcode-6360728-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Exploit.Shellcode.3.2FD1F607
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanDeepScan:Generic.Exploit.Shellcode.3.2FD1F607
RisingTrojan.Crypto!8.364 (RDMK:cmRtazqqaLuXjmJRmlUExcDSzaV0)
Ad-AwareDeepScan:Generic.Exploit.Shellcode.3.2FD1F607
SophosML/PE-A + Mal/EncPk-ND
ComodoTrojWare.Win32.Rozena.A@4jwdqr
F-SecureTrojan.TR/Crypt.ZPACK.Gen
TrendMicroBKDR_SWRORT.SM
McAfee-GW-EditionSwrort.d
FireEyeGeneric.mg.4997410f78e6bec7
EmsisoftDeepScan:Generic.Exploit.Shellcode.3.2FD1F607 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitDeepScan:Generic.Exploit.Shellcode.3.2FD1F607
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Exploit.Shellcode.3.2FD1F607
AhnLab-V3Backdoor/Win32.Bifrose.R12476
VBA32Trojan.Swrort
ALYacDeepScan:Generic.Exploit.Shellcode.3.2FD1F607
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1592655575
TrendMicro-HouseCallBKDR_SWRORT.SM
TencentMalware.Win32.Gencirc.10b3f98b
YandexTrojan.GenAsa!O0/tdGI4TGA
IkarusTrojan.Win32.Swrort
MaxSecureTrojan.Malware.300983.susgen
FortinetMalwThreat!0971IV
BitDefenderThetaGen:NN.ZexaF.34606.cmKfau4N!Vmi
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Generic.Exploit.Shellcode.3.2FD1F607?

Generic.Exploit.Shellcode.3.2FD1F607 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment