Categories: Malware

Should I remove “Generic.ShellCode.Marte.J.975FBE9D”?

The Generic.ShellCode.Marte.J.975FBE9D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.J.975FBE9D virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Njrat malware family

How to determine Generic.ShellCode.Marte.J.975FBE9D?


File Info:

name: 64090AA07DBFB9CFBB9F.mlwpath: /opt/CAPEv2/storage/binaries/c44e10ab0a68d393839b5d8a649883e1b1ca8dce00ab838e0c8c6e03c04ec181crc32: 5726AA9Bmd5: 64090aa07dbfb9cfbb9f798bcefb816dsha1: 030a601adc8c9254dc67552aafa57730c4c36299sha256: c44e10ab0a68d393839b5d8a649883e1b1ca8dce00ab838e0c8c6e03c04ec181sha512: 1b1f2f257a69f7a0bdadc2e46f466fb6520a53fe6107ad56f5b4f06d85604fc2bc8658df1ce9b1f38cfe82a2efd9d87ba222e754810012cddbbf038f1d56e968ssdeep: 1536:OL6Ma0NRWuwzRRkyzFS8gNP0NIi6bSQ8OoAKYDPZRM1UitZR1:q6Ma80lRRZzFPk2I111KYTI1Uk1type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1C9B38D8A7A85E654C86C0E30C571C0E04733B0DB9C5688967AE4755FAEF7353A813B7Bsha3_384: 7d59ca4ea69d71c10e5b0823242b3fc7230e8822579f0a82c0e63138374ed143a0515b01b73d9d52de8fb72aec264c7cep_bytes: 8bec609ce9932b000000000000000000timestamp: 2020-12-26 10:35:27

Version Info:

0: [No Data]

Generic.ShellCode.Marte.J.975FBE9D also known as:

Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Generic.mAmC
tehtris Generic.Malware
MicroWorld-eScan Generic.ShellCode.Marte.J.975FBE9D
FireEye Generic.mg.64090aa07dbfb9cf
CAT-QuickHeal Trojan.Generic.TRFH5
McAfee GenericRXEP-EK!64090AA07DBF
Cylance Unsafe
Sangfor Worm.Win32.Save.a
K7AntiVirus Trojan ( 004915961 )
Alibaba Trojan:Win32/Bladabindi.374
K7GW Trojan ( 004915961 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu MSIL.Backdoor.Bladabindi.a
VirIT Backdoor.Win32.Generic.AWM
Cyren W32/MSIL_Bladabindi.ER.gen!Eldorado
Symantec Backdoor.Ratenjay
Elastic Windows.Trojan.Njrat
ESET-NOD32 a variant of MSIL/Bladabindi.AS
APEX Malicious
ClamAV Win.Packed.Generic-9795615-0
Kaspersky Trojan.MSIL.Disfa.bqg
BitDefender Generic.ShellCode.Marte.J.975FBE9D
NANO-Antivirus Trojan.Win32.Disfa.dtznyx
Avast MSIL:Agent-DRD [Trj]
Tencent Trojan.Msil.Bladabindi.za
Ad-Aware Generic.ShellCode.Marte.J.975FBE9D
Sophos Mal/Generic-S + Troj/Bbindi-W
Comodo Backdoor.MSIL.Bladabindi.A@566ygc
DrWeb BackDoor.Bladabindi.13678
VIPRE Generic.MSIL.Bladabindi.975FBE9D
TrendMicro TROJ_GEN.R002C0CKN22
McAfee-GW-Edition BehavesLike.Win32.Infected.ch
Trapmine malicious.moderate.ml.score
Emsisoft Trojan.Bladabindi (A)
Ikarus Trojan.MSIL.Bladabindi
GData MSIL.Backdoor.Bladabindi.AV
Jiangmin Trojan.Inject.sfc
Google Detected
Avira TR/Dropper.Gen7
MAX malware (ai score=81)
Antiy-AVL Trojan/MSIL.Disfa.bqg
Arcabit Generic.ShellCode.Marte.J.975FBE9D
ViRobot Backdoor.Win32.Bladabindi.Gen.A
ZoneAlarm HEUR:Trojan-Spy.MSIL.KeyLogger.gen
Microsoft Backdoor:MSIL/Bladabindi
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Disfa.C5313905
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.34796.gmW@aC9Z!Boi
ALYac Generic.MSIL.Bladabindi.975FBE9D
Malwarebytes Bladabindi.Backdoor.Bot.DDS
TrendMicro-HouseCall TROJ_GEN.R002C0CKN22
Rising Backdoor.njRAT!1.9E49 (CLASSIC)
Yandex Trojan.AvsMofer.dd6520
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet MSIL/Bladabindi.AS!tr
AVG MSIL:Agent-DRD [Trj]
Cybereason malicious.07dbfb
Panda Trj/CI.A

How to remove Generic.ShellCode.Marte.J.975FBE9D?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Tedy.551777 (file analysis)

The Tedy.551777 is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago

About “Lazy.518842” infection

The Lazy.518842 is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago

HackTool:Win32/Malgent!MSR information

The HackTool:Win32/Malgent!MSR is considered dangerous by lots of security experts. When this infection is active,…

31 mins ago

Barys.27333 malicious file

The Barys.27333 is considered dangerous by lots of security experts. When this infection is active,…

36 mins ago

How to remove “Win32/Kryptik.GKHS”?

The Win32/Kryptik.GKHS is considered dangerous by lots of security experts. When this infection is active,…

36 mins ago

What is “Malware.AI.1865006162”?

The Malware.AI.1865006162 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago