Malware

Generic.ShellCode.Marte.J.4B71B693 (file analysis)

Malware Removal

The Generic.ShellCode.Marte.J.4B71B693 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.J.4B71B693 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generic.ShellCode.Marte.J.4B71B693?


File Info:

name: 27BCD2D23C0D5A2D1147.mlw
path: /opt/CAPEv2/storage/binaries/fc0daadf2d83e239f931f4dbaa5f8068f171abcd9457adaf20677aa8af19ecd5
crc32: 303C78CD
md5: 27bcd2d23c0d5a2d114767cc60c64830
sha1: e07906425d5e8cb5a209c9d7b841e3972687afee
sha256: fc0daadf2d83e239f931f4dbaa5f8068f171abcd9457adaf20677aa8af19ecd5
sha512: 1717ef430baaebc0ef850ae45d5beefdc054097a686e615a1fdb96046078b4ad21b19297501ec0972f9425e1faefeab454e84e1479ee9418b86003191350ccd6
ssdeep: 6144:+9yyNfCSSyIGdnhHYKfZ/7AVByak0j84PGunHMzTy1Wr:+9yYTSAHYKfZ/7AGb0jX7Hfa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187749E127791C432C26A25368956D7B4A6BAB4309FE485C77BD0173DDF702D2BA3A30B
sha3_384: efdda8c27458eaa40eff585c4d2fd34506ba1177bc972b7071970e82b5c4eb482b48a893d4c30dd96c24c8a1c39e1271
ep_bytes: 8bec609ce959860300ff8bff558bec6a
timestamp: 2012-08-27 10:35:48

Version Info:

CompanyName: Windows Application
FileDescription: Windows Application
FileVersion: 3, 4, 5, 33
InternalName: winvnc.exe
LegalCopyright: Copyright (C) 2005
OriginalFilename: winvnc.exe
ProductName: winvnc
ProductVersion: 1, 11, 1, 111
Translation: 0x0409 0x04b0

Generic.ShellCode.Marte.J.4B71B693 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.ShellCode.Marte.J.4B71B693
ALYacGeneric.ShellCode.Marte.J.4B71B693
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.25d5e8
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Agent.OBF
APEXMalicious
ClamAVWin.Dropper.Memery-9979246-0
BitDefenderGeneric.ShellCode.Marte.J.4B71B693
AvastWin32:Agent-AREI [Spy]
Ad-AwareGeneric.ShellCode.Marte.J.4B71B693
EmsisoftGeneric.ShellCode.Marte.J.4B71B693 (B)
DrWebTrojan.KeyLogger.16437
VIPREGeneric.ShellCode.Marte.J.4B71B693
FireEyeGeneric.mg.27bcd2d23c0d5a2d
GoogleDetected
AviraHEUR/AGEN.1242849
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitGeneric.ShellCode.Marte.J.4B71B693
GDataGeneric.ShellCode.Marte.J.4B71B693
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R535546
MAXmalware (ai score=85)
MalwarebytesMalware.AI.2808826819
RisingSpyware.Agent!8.C6 (TFE:5:sp6GPdz6sPL)
YandexTrojan.GenAsa!1VocAVpu4V8
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenKryptik.GCTV!tr
BitDefenderThetaGen:NN.ZexaF.34796.wu0@aG!tjyai
AVGWin32:Agent-AREI [Spy]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.ShellCode.Marte.J.4B71B693?

Generic.ShellCode.Marte.J.4B71B693 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment