Malware

How to remove “Generic.ShellCode.Marte.H.89A65F37”?

Malware Removal

The Generic.ShellCode.Marte.H.89A65F37 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.H.89A65F37 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.ShellCode.Marte.H.89A65F37?


File Info:

name: 067DAF2FAFC65D032921.mlw
path: /opt/CAPEv2/storage/binaries/bd06884004f98963e1ba3b53028d538b2da5270b4daced0e7a609638bcee5f65
crc32: 938002BF
md5: 067daf2fafc65d032921b02caedd7d5b
sha1: a30e0ea1b5a67f9517c871dc1bc20f1517cda6d4
sha256: bd06884004f98963e1ba3b53028d538b2da5270b4daced0e7a609638bcee5f65
sha512: 84da3381dd877c52b89b71df104310dc2bddc92ede955fe7d0915863db3cf68a26d6a9e0f706bf783f40130e13b982827d6bf5a952895776716b6b46fc5df39b
ssdeep: 384:dA8AuVIWlddyqoWBUZNoZao+1sqn6Ud+vgP4ndtQiXbaB0fETvf:gspddRZo/OvgAvpbm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T131F2D4D87DA55DD6EA01527EA5F7C2266B3CF0E087034B83763076394B13AD23AE524B
sha3_384: cf2fc61219468f4feddf0de8699905c764cab96a3d6c9a1c3d611b67f1ac446c5db8158a7303781af5288b157f471690
ep_bytes: 83ec1cc7042401000000ff1508714000
timestamp: 1970-03-16 08:04:02

Version Info:

0: [No Data]

Generic.ShellCode.Marte.H.89A65F37 also known as:

LionicTrojan.Win32.Cometer.4!c
MicroWorld-eScanDeepScan:Generic.ShellCode.Marte.H.89A65F37
ClamAVWin.Trojan.MSShellcode-6360730-0
ALYacDeepScan:Generic.ShellCode.Marte.H.89A65F37
MalwarebytesGeneric.Malware/Suspicious
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (D)
SymantecHacktool
ESET-NOD32a variant of Win32/Rozena.BMG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.ShellCode.Marte.H.89A65F37
NANO-AntivirusTrojan.Win32.Cometer.fmqlwb
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Qsmw
EmsisoftDeepScan:Generic.ShellCode.Marte.H.89A65F37 (B)
F-SecureTrojan.TR/Meterpreter.cnyzq
VIPREDeepScan:Generic.ShellCode.Marte.H.89A65F37
McAfee-GW-EditionPacked-SC!067DAF2FAFC6
FireEyeGeneric.mg.067daf2fafc65d03
SophosATK/Avet-A
IkarusTrojan.Win32.Meterpreter
JiangminTrojan.Cometer.ep
AviraTR/Meterpreter.cnyzq
Antiy-AVLTrojan/Win32.Cometer
MicrosoftTrojan:Win32/Meterpreter.gen!C
ArcabitDeepScan:Generic.ShellCode.Marte.H.89A65F37
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.ShellCode.Marte.H.89A65F37
GoogleDetected
McAfeePacked-SC!067DAF2FAFC6
MAXmalware (ai score=87)
VBA32Trojan.Cometer
PandaTrj/GdSda.A
RisingTrojan.Generic@AI.80 (RDMK:cmRtazp96HtiB3kMCXv+LKccI5d8)
YandexTrojan.GenAsa!PGDygsfM0Go
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PACKED.SC!tr
AVGWin32:Malware-gen
Cybereasonmalicious.fafc65
DeepInstinctMALICIOUS

How to remove Generic.ShellCode.Marte.H.89A65F37?

Generic.ShellCode.Marte.H.89A65F37 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment