Malware

Generic.ShellCode.Marte.J.D3A03AAB information

Malware Removal

The Generic.ShellCode.Marte.J.D3A03AAB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.J.D3A03AAB virus can do?

  • Unconventionial language used in binary resources: Chinese (Singapore)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.ShellCode.Marte.J.D3A03AAB?


File Info:

name: BCA926EA1B7AB8C99AD5.mlw
path: /opt/CAPEv2/storage/binaries/fa89232af5aeb1a69ed8d8262f82c14e12295ca2e013ff406fdd88ecb5a0d9f1
crc32: 6D761B53
md5: bca926ea1b7ab8c99ad564a3d47c2960
sha1: 7bb5a5549ce7b5223ab642680d83e7eee888c065
sha256: fa89232af5aeb1a69ed8d8262f82c14e12295ca2e013ff406fdd88ecb5a0d9f1
sha512: ba745c2f7e5ed53aee3e8b6cc633acb98f24fc9a9dd06e6078938ba617a26d13ad2f8e80dd4e6fe2716d844ca4069796896010113533e854140b64e755160931
ssdeep: 3072:eISHFrplaYYmAtvaRZzFPk2I111KYTI1Uk10:epHFtnYkHMzTy10
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137E3AE8A748B9165CC5C0C30C461D4F54B3B6897AED65887BFE4FA0E6DF2262B027637
sha3_384: 67b83b3b66050c6f4befeebf3d24f2c96a0f816419a307d3ccdb7998807207f7aaf099184c20ab12c6e7151bcdb3582f
ep_bytes: 8bec609ce946a300000068c847400064
timestamp: 2019-03-04 02:58:26

Version Info:

0: [No Data]

Generic.ShellCode.Marte.J.D3A03AAB also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGeneric.ShellCode.Marte.J.D3A03AAB
ClamAVWin.Dropper.Memery-9979246-0
ALYacGeneric.ShellCode.Marte.J.D3A03AAB
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.49ce7b
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.TQE
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGeneric.ShellCode.Marte.J.D3A03AAB
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:MalOb-FE [Cryp]
Ad-AwareGeneric.ShellCode.Marte.J.D3A03AAB
EmsisoftGeneric.ShellCode.Marte.J.D3A03AAB (B)
VIPREGeneric.ShellCode.Marte.J.D3A03AAB
McAfee-GW-EditionGenericRXHJ-JB!BCA926EA1B7A
FireEyeGeneric.mg.bca926ea1b7ab8c9
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Win32.Agent
MicrosoftPWS:Win32/Zbot!ml
ArcabitGeneric.ShellCode.Marte.J.D3A03AAB
GDataGeneric.ShellCode.Marte.J.D3A03AAB
GoogleDetected
McAfeeGenericRXHJ-JB!BCA926EA1B7A
MAXmalware (ai score=89)
VBA32BScope.Trojan.Agent
MalwarebytesMalware.Heuristic.1001
RisingTrojan.Kryptik!1.AAD1 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.GCTV!tr
BitDefenderThetaGen:NN.ZexaF.34796.jqW@aeWKl1ij
AVGWin32:MalOb-FE [Cryp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.ShellCode.Marte.J.D3A03AAB?

Generic.ShellCode.Marte.J.D3A03AAB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment