Malware

Generic.ShellCode.Marte.4.79CF9736 malicious file

Malware Removal

The Generic.ShellCode.Marte.4.79CF9736 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.4.79CF9736 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generic.ShellCode.Marte.4.79CF9736?


File Info:

name: 40CD75B1B9D5CC5C74DA.mlw
path: /opt/CAPEv2/storage/binaries/984c515d4df9fc9f1de9d9e0350ba488b7610da1b1463fa8e836bee3e779a4ee
crc32: 863068C9
md5: 40cd75b1b9d5cc5c74da0a00b80adbd9
sha1: a90a601b237199355533d477973b5f44d264ccaf
sha256: 984c515d4df9fc9f1de9d9e0350ba488b7610da1b1463fa8e836bee3e779a4ee
sha512: 53eceed18dca7ba1226602aa4a70c1e02ef625da9dd8ccff8e8b0ff05518884a29c7044f73b2c7ed01a3a8d5100694400baf4ec288be98e6b1cb0fce1ccd67f3
ssdeep: 48:1YLrfPKQtDTGawswfmdFdCK+UXsUrRkmZMcFgurx/F:1a3tHGaJHdLxXFNkmmMrN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5810C6E7080D3B7CD691EB91D974C51DFF48A544DE8AD2A8F5C09FC93B4AE0D006B48
sha3_384: 9ad11f1a335499cf4ab4187eb4d2d6afb661df01e02a35908a5f3ff90932ecc7bcb3b88ce60717ba8af63d4740b8dd30
ep_bytes: 5589e583ec2056e8f100000089c68d86
timestamp: 2024-04-24 14:58:09

Version Info:

0: [No Data]

Generic.ShellCode.Marte.4.79CF9736 also known as:

BkavW32.AIDetectMalware
AVGWin32:CrypterX-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.ShellCode.Marte.4.79CF9736
FireEyeGeneric.mg.40cd75b1b9d5cc5c
SkyhighBehavesLike.Win32.VTFlooder.xm
McAfeeGenericRXGU-VO!40CD75B1B9D5
Cylanceunsafe
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win64/Meterpreter.4efbc9e2
K7GWTrojan ( 00121dea1 )
K7AntiVirusTrojan ( 00121dea1 )
SymantecMeterpreter
ESET-NOD32a variant of Win32/Rozena.BLY
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyUDS:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.ShellCode.Marte.4.79CF9736
TencentTrojan.Win32.MSF.16000687
EmsisoftDeepScan:Generic.ShellCode.Marte.4.79CF9736 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREDeepScan:Generic.ShellCode.Marte.4.79CF9736
Trapminemalicious.high.ml.score
SophosATK/Swrort-BE
Paloaltogeneric.ml
WebrootW32.Malware.Gen
VaristW32/Rozena.AH.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=87)
Kingsoftmalware.kb.a.988
MicrosoftTrojan:Win64/Meterpreter.B
GridinsoftTrojan.Win32.Shellcode.sa
ArcabitDeepScan:Generic.ShellCode.Marte.4.79CF9736
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.ShellCode.Marte.4.79CF9736
GoogleDetected
AhnLab-V3Trojan/Win32.Rozena.R254997
BitDefenderThetaGen:NN.ZexaF.36804.amW@aeKRA@m
ALYacDeepScan:Generic.ShellCode.Marte.4.79CF9736
VBA32BScope.Trojan.Meterpreter
MalwarebytesTrojan.ShellCode
PandaTrj/Genetic.gen
RisingTrojan.Meterpreter!8.E532 (TFE:2:IVMWDZo37YL)
YandexTrojan.GenAsa!RuXWX5C6OxI
IkarusTrojan.Win32.Rozena
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Rozena.ABC!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Rozena.BET

How to remove Generic.ShellCode.Marte.4.79CF9736?

Generic.ShellCode.Marte.4.79CF9736 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment