Malware

Generic.Exploit.Shellcode.PE.1.DC017288 removal tips

Malware Removal

The Generic.Exploit.Shellcode.PE.1.DC017288 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Exploit.Shellcode.PE.1.DC017288 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Generic.Exploit.Shellcode.PE.1.DC017288?


File Info:

name: 42096A4A5C2C669E5A9A.mlw
path: /opt/CAPEv2/storage/binaries/90ff88e95ff81233c203e741425f38ae7784db17d89d4e2c07153d614c8286f1
crc32: ED65E7A9
md5: 42096a4a5c2c669e5a9aa75847b6b3fc
sha1: ae6cb96dc651d2a25bc71155198af499270f742e
sha256: 90ff88e95ff81233c203e741425f38ae7784db17d89d4e2c07153d614c8286f1
sha512: 2415be4405a74384ff3608e458ede4cf52ad4eda41fcbe14259cf864fdb1fd2f1f4aec28ecd249f5abbf78013cc9fbccdbceb33b6054c7c6daa187342f706ac0
ssdeep: 384:qfY9Ew07FzSmmfuNA779SGjJDZlRfjEU5BMDHDe9prVsOpdPBG4pLGwhqvQSoHTG:qwEw0cmmb79SGJDTR/oe9hv/AYzzsTB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7E25B15CC3381E6E9E62831074ABF2BDC6DEE3286E848B743907D856C9D265F4252DB
sha3_384: 9169cbdda81d80e446ca4cd2bd847537de13b258007eccb56a67b48ff1313fa3b7a1438e2b80e467a152aa19998a8ca0
ep_bytes: e8ade3ffff33c0c21000558bec81ec2c
timestamp: 2020-01-08 20:45:13

Version Info:

0: [No Data]

Generic.Exploit.Shellcode.PE.1.DC017288 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Androm.m!c
MicroWorld-eScanGeneric.Exploit.Shellcode.PE.1.DC017288
FireEyeGeneric.mg.42096a4a5c2c669e
McAfeeGenericRXJM-IV!42096A4A5C2C
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055d8481 )
AlibabaBackdoor:Win32/Androm.0400171f
K7GWTrojan ( 0055d8481 )
Cybereasonmalicious.a5c2c6
BitDefenderThetaAI:Packer.A8A77C111E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ABIW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Androm.gen
BitDefenderGeneric.Exploit.Shellcode.PE.1.DC017288
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentWin32.Backdoor.Androm.Oyon
Ad-AwareGeneric.Exploit.Shellcode.PE.1.DC017288
EmsisoftGeneric.Exploit.Shellcode.PE.1.DC017288 (B)
ComodoMalware@#tcgu34snt8e2
F-SecureHeuristic.HEUR/AGEN.1220850
ZillyaTrojan.Agent.Win32.1273808
McAfee-GW-EditionGenericRXJM-IV!42096A4A5C2C
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGeneric.Exploit.Shellcode.PE.1.DC017288
JiangminGeneric.Exploit.d
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1220850
Antiy-AVLTrojan/Generic.ASMalwS.2FDC565
MicrosoftTrojan:Win32/Occamy.C90
AhnLab-V3Trojan/Win32.RL_Androm.R327966
Acronissuspicious
VBA32BScope.Malware-Cryptor.Bicololo.2513
ALYacGeneric.Exploit.Shellcode.PE.1.DC017288
MAXmalware (ai score=88)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
RisingBackdoor.Androm!8.113 (CLOUD)
YandexTrojan.GenAsa!idwRze2UGMQ
IkarusTrojan.Win32.Tinukebot
MaxSecureTrojan.Malware.73688777.susgen
FortinetW32/Androm.ABIW!tr.bdr
AVGWin32:AgentDropper-E [Drp]
AvastWin32:AgentDropper-E [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Exploit.Shellcode.PE.1.DC017288?

Generic.Exploit.Shellcode.PE.1.DC017288 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment