Malware

Generic.Exploit.Shellcode.3.C8E185D5 removal guide

Malware Removal

The Generic.Exploit.Shellcode.3.C8E185D5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Exploit.Shellcode.3.C8E185D5 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Generic.Exploit.Shellcode.3.C8E185D5?


File Info:

crc32: F3D0777B
md5: 82a187f71b310d40e796f4b8e185f26d
name: 82A187F71B310D40E796F4B8E185F26D.mlw
sha1: 17ce1a07f924bd61b0d372a8541db2620d3f7a42
sha256: 427f29c38b21f42df10fc99c53d3a9bf9e7efd3aa338a1cabdb91c875317d3d9
sha512: 53768fdab9c0379610f5deac6fa22badd98157c0550f9ca14e8b5086a23de30ce5f1681db9ea5470bd8bfd3b43718dbf975ad486abfcc7e63dc292029c31cf82
ssdeep: 768:InWr63ETzBdlQxtoTGcmar9hKHQ0aEtbd3a7Pn6Zw6S6qXuGEVaHbLJ/oN2D5c5:Ik6UTzzlgy7mar9z0aAqL6dgeGEoXJ/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 2009 The Apache Software Foundation.
InternalName: ab.exe
FileVersion: 2.2.14
CompanyName: Apache Software Foundation
Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
FileDescription: ApacheBench command line utility
OriginalFilename: ab.exe
Translation: 0x0409 0x04b0

Generic.Exploit.Shellcode.3.C8E185D5 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004c49f81 )
Elasticmalicious (high confidence)
DrWebTrojan.Swrort.1
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Swrort.A
McAfeeSwrort.d
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004c49f81 )
Cybereasonmalicious.71b310
CyrenW32/Swrort.B.gen!Eldorado
SymantecPacked.Generic.347
ESET-NOD32a variant of Win32/Rozena.ED
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.Swrort-5710536-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Exploit.Shellcode.3.C8E185D5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGeneric.Exploit.Shellcode.3.C8E185D5
TencentMalware.Win32.Gencirc.10b3f98b
Ad-AwareGeneric.Exploit.Shellcode.3.C8E185D5
SophosMal/Swrort-C
ComodoTrojWare.Win32.Rozena.A@4jwdqr
BitDefenderThetaGen:NN.ZexaF.34670.cmKfaGOfdjai
VIPRETrojan.Win32.Swrort.B (v)
TrendMicroBackdoor.Win32.SWRORT.SMAL01
McAfee-GW-EditionBehavesLike.Win32.Virut.pc
FireEyeGeneric.mg.82a187f71b310d40
EmsisoftGeneric.Exploit.Shellcode.3.C8E185D5 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Meterpreter
ArcabitGeneric.Exploit.Shellcode.3.C8E185D5
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.16Y83VL
AhnLab-V3Backdoor/Win32.Bifrose.R12476
Acronissuspicious
VBA32Trojan.Swrort
MAXmalware (ai score=81)
MalwarebytesTrojan.Rozena
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.Win32.SWRORT.SMAL01
RisingTrojan.Crypto!8.364 (RDMK:cmRtazrahWexU75vGxG95VSWIbgY)
YandexTrojan.GenAsa!O0/tdGI4TGA
IkarusExploit.PDF
FortinetMalwThreat!df3bIV
AVGWin32:Evo-gen [Susp]
Qihoo-360HEUR/QVM11.1.92A8.Malware.Gen

How to remove Generic.Exploit.Shellcode.3.C8E185D5?

Generic.Exploit.Shellcode.3.C8E185D5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment