Malware

Generic.ShellCode.Marte.H.5781D822 removal instruction

Malware Removal

The Generic.ShellCode.Marte.H.5781D822 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.H.5781D822 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.ShellCode.Marte.H.5781D822?


File Info:

name: 8909068738A0B77F14B4.mlw
path: /opt/CAPEv2/storage/binaries/91bd5a01d8651323c70905225e6991b878cfca6404689c9a6cbbd4dcf808b992
crc32: 40E74D59
md5: 8909068738a0b77f14b4d97ad9dcc3f9
sha1: 1e897daebcf2822194392ea56c82969d4e6db538
sha256: 91bd5a01d8651323c70905225e6991b878cfca6404689c9a6cbbd4dcf808b992
sha512: 67dd3d0007c24ec6b20f2a0b53420420796acd0a6ecb68684076323054299fc1d33bc2b8695c27abea5f425132104c3f5129931a05ae134d674f9b0c01cd3d57
ssdeep: 768:I0tBQpJojd/IlTzs5GTbFSDijPA7geHQ68sf+1ap9tnREA9EF+VIxsb6YOOgjnb3:I0gcxwJUsbFSG7A7nPH9tREpg6DFnou/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D23E14BA1FE565AF5EB3174467975984932FE28DE78CB7C81A810798832A61A808337
sha3_384: 1e9c4c990a8a728ad5a3710ed14a4ec9c17f23c852edfeeee7bfe57b0b54830a20eb2e23c161f8cedb10f4e0c0f51b7b
ep_bytes: 60be00e040008dbe0030ffff5789e58d
timestamp: 2009-08-30 16:56:53

Version Info:

Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName: Apache Software Foundation
FileDescription: ApacheBench command line utility
FileVersion: 2.2.14
InternalName: ab.exe
LegalCopyright: Copyright 2009 The Apache Software Foundation.
OriginalFilename: ab.exe
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
Translation: 0x0409 0x04b0

Generic.ShellCode.Marte.H.5781D822 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGeneric.ShellCode.Marte.H.5781D822
CAT-QuickHealTrojan.Swrort.A
SkyhighSwrort.d
ALYacGeneric.ShellCode.Marte.H.5781D822
Cylanceunsafe
VIPREGeneric.ShellCode.Marte.H.5781D822
SangforTrojan.Win32.Save.a
Cybereasonmalicious.ebcf28
SymantecTrojan Horse
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Rozena.AA
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.ShellCode.Marte.H.5781D822
NANO-AntivirusTrojan.Win32.Shellcode.ewfvwj
AvastWin32:Meterpreter-C [Trj]
TencentTrojan.Win32.Metasploit_heur.16000690
EmsisoftGeneric.ShellCode.Marte.H.5781D822 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Swrort.1
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8909068738a0b77f
SophosATK/SwrortPk-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.12141ZK
WebrootW32.Trojan.Swrort
VaristW32/Swrort.D.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.Rozena
XcitiumTrojWare.Win32.Rozena.A@4jwdqr
ArcabitGeneric.ShellCode.Marte.H.5781D822
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Backdoor/Win32.Bifrose.R12476
McAfeeSwrort.d
MAXmalware (ai score=85)
VBA32Trojan.Swrort
RisingTrojan.Crypto!8.364 (TFE:5:qRUE1u5wYD)
YandexTrojan.GenAsa!O0/tdGI4TGA
IkarusTrojan.Win32.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rozena.ABV!tr
BitDefenderThetaGen:NN.ZexaF.36608.cmKfauYXTWbi
AVGWin32:Meterpreter-C [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.ShellCode.Marte.H.5781D822?

Generic.ShellCode.Marte.H.5781D822 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment