Malware

Generic.Exploit.Shellcode.3.D6AE3EA4 removal

Malware Removal

The Generic.Exploit.Shellcode.3.D6AE3EA4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Exploit.Shellcode.3.D6AE3EA4 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Generic.Exploit.Shellcode.3.D6AE3EA4?


File Info:

name: 13ACE47940A7791D07D2.mlw
path: /opt/CAPEv2/storage/binaries/e606f42f04eb52c0d547fdb15619c869a79a84fd69b21b5d3964bf8bcdb202f0
crc32: C50CC6CB
md5: 13ace47940a7791d07d2eab34be4429a
sha1: a598e0415fdb9e6c8f6a8a817b6188fbeea130b9
sha256: e606f42f04eb52c0d547fdb15619c869a79a84fd69b21b5d3964bf8bcdb202f0
sha512: 898ca9f07cf808d8c654587016d924ca55528ea083624296b85d0b4d36d7476411d4eef70ff1af867dd6455616c6268a1598ef1f63487d2720d5e6bbd0310adf
ssdeep: 12288:kL8YsoMJOBRFVKkkk378ovcJoKHC5GT1YZ4doS:kT/BRlXvmoK7A
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D494236220BE5F6FF4CB913A1AAAB4DC9B05218CD71167F91B4F227B07208FC5D54A72
sha3_384: d7f715fc2877385cef48cacd5042758a6577921395239ad058c3fe000b55dd3a8553b5389fda83c1332f438f17f6ce8c
ep_bytes: 60be15004f008dbeeb0ff1ff5789e58d
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Generic.Exploit.Shellcode.3.D6AE3EA4 also known as:

CynetMalicious (score: 100)
ALYacDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.940a77
Elasticmalicious (moderate confidence)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
MicroWorld-eScanDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
Ad-AwareDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
EmsisoftDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4 (B)
FireEyeDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
GDataDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
ArcabitDeepScan:Generic.Exploit.Shellcode.3.D6AE3EA4
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win32.Wacatac.C4190983
MAXmalware (ai score=88)
RisingTrojan.Generic@AI.96 (RDMK:cmRtazpDDiAV8jp9nNpc6zkYN4wr)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34638.zmGfaWlHqml

How to remove Generic.Exploit.Shellcode.3.D6AE3EA4?

Generic.Exploit.Shellcode.3.D6AE3EA4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment