Malware

Generic.ShellCode.Marte.3.09E40248 removal instruction

Malware Removal

The Generic.ShellCode.Marte.3.09E40248 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.3.09E40248 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generic.ShellCode.Marte.3.09E40248?


File Info:

name: EE13AAC6EE46DDBFBACC.mlw
path: /opt/CAPEv2/storage/binaries/6c1f76c3a2ea792c88c96ff8472c9c4ff33be8d409d3f6cb9741c58f17d7378c
crc32: B672F08B
md5: ee13aac6ee46ddbfbacc55fd2c7b8b35
sha1: 683eaf87a06f17d2f1758afb2798427688282944
sha256: 6c1f76c3a2ea792c88c96ff8472c9c4ff33be8d409d3f6cb9741c58f17d7378c
sha512: de3fbf280745b7b81251cfb8603904ab12dbb989d81fafc4d784b867a75c78ea94f05c95f58ba923d76bc3465fc779d207c839cf38f32ae1a65f7c2a0a324bd9
ssdeep: 1536:t06OEqtFy0Q4isD2ISCRGmrBsLSBPIoss6/xLGK11:P0nRGmk1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BEA318C7FAD6ADA7CA09063E89BA8319233DF7D80B824B034D7876341A575D06ED7247
sha3_384: 679ecaa7dba0d44c44512d1aeb6a3b804fd45a9b8231750420b809bba789b2ed34824e3624925b3b0ae40e8de68c8726
ep_bytes: c7056460400000000000e961fdffff90
timestamp: 2024-04-01 02:07:23

Version Info:

0: [No Data]

Generic.ShellCode.Marte.3.09E40248 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Marte.4!c
ElasticWindows.Trojan.Metasploit
MicroWorld-eScanGeneric.ShellCode.Marte.3.09E40248
FireEyeGeneric.ShellCode.Marte.3.09E40248
SkyhighArtemis!Trojan
McAfeeArtemis!EE13AAC6EE46
Cylanceunsafe
ZillyaTrojan.Rozena.Win32.215070
SangforHackTool.Win32.Reverse_Bin_v2_5_through_v4_x.uwccg
AlibabaTrojan:Win32/CobaltStrike.5c89
K7GWTrojan ( 005766041 )
K7AntiVirusTrojan ( 005766041 )
BitDefenderThetaGen:NN.ZexaF.36804.g8Y@a8ttFPl
SymantecMeterpreter
ESET-NOD32a variant of Win32/Rozena.AZP
APEXMalicious
AvastWin32:Meterpreter-B [Expl]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.ShellCode.Marte.3.09E40248
NANO-AntivirusTrojan.Win32.Rozena.klcgmt
TencentTrojan.Win32.Metasploit_heur.16000690
EmsisoftGeneric.ShellCode.Marte.3.09E40248 (B)
F-SecureTrojan:W32/Payload.A
VIPREGeneric.ShellCode.Marte.3.09E40248
TrendMicroBackdoor.Win32.COBEACON.SMD
SophosATK/Swrort-GA
Paloaltogeneric.ml
JiangminTrojan.Generic.hqgax
VaristW32/Rozena.HZ.gen!Eldorado
AviraHEUR/AGEN.1367120
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Rozena
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Meterpreter.RPZ!MTB
ArcabitGeneric.ShellCode.Marte.3.09E40248
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.12141ZK
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R596585
ALYacGeneric.ShellCode.Marte.3.09E40248
GoogleDetected
VBA32Trojan.Meterpreter
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingHackTool.Swrort!1.6477 (CLASSIC)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Rozena.AZP!tr
AVGWin32:Meterpreter-B [Expl]
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/CobaltStrike.reverse.A

How to remove Generic.ShellCode.Marte.3.09E40248?

Generic.ShellCode.Marte.3.09E40248 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment