Spy

Spyware.BlackShadesNET removal instruction

Malware Removal

The Spyware.BlackShadesNET is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.BlackShadesNET virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Spyware.BlackShadesNET?


File Info:

name: 73C59D71D1901A319EA6.mlw
path: /opt/CAPEv2/storage/binaries/9cd0f72205e194dba8164a5d867855f176bde9c57850292ed7cc77cbb9aae717
crc32: DE716633
md5: 73c59d71d1901a319ea640a3b37108c5
sha1: de8c4d5ab27d0d9c7ca231e1327015bb46334be3
sha256: 9cd0f72205e194dba8164a5d867855f176bde9c57850292ed7cc77cbb9aae717
sha512: fa418701c78d9d226c5a11d47c4a29076d4f449a9ead7cf6c8f92f3071e903dd58297f11eba6ae5b813c454c64d39a10a8d4a13121c23f92edbcc1bf5e4f166a
ssdeep: 12288:9qkREEkMPcgCCq+FRk5YzcOH35N2TpLOW0UUfaelPb7elo:93Rq+0YzrOTpLz0PvMl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108F49E24EBF98117E2BF1B7184B155446BB9BC16A813DF9C4C80B7BE58327418A12B7F
sha3_384: b4c7f3a58bd5a2fde374215c3f53e78d028b33ae3956c465f0379cdbbb6e5318f3a2bf1960c6120b72ad804ccc1601b9
ep_bytes: ff254c45450000000000000000002045
timestamp: 2019-06-24 11:27:18

Version Info:

0: [No Data]

Spyware.BlackShadesNET also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Mardom.MN.18
FireEyeGeneric.mg.73c59d71d1901a31
SkyhighBehavesLike.Win32.Generic.bh
McAfeeTrojan-FRIO!73C59D71D190
MalwarebytesSpyware.BlackShadesNET
ZillyaTrojan.Kryptik.Win32.1707138
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005547d91 )
AlibabaTrojan:Win32/Maldoc.ali2000008
K7GWTrojan ( 005547d91 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Mardom.MN.18
VirITTrojan.Win32.Dnldr30.GOZ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.SQK
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
BitDefenderGen:Trojan.Mardom.MN.18
NANO-AntivirusTrojan.Win32.NanoBot.fvlmzn
AvastWin32:RATX-gen [Trj]
TencentMsil.Backdoor.Nanobot.Rnkl
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Nanocore.kdw
DrWebTrojan.DownLoader30.4445
VIPREGen:Trojan.Mardom.MN.18
TrendMicroTrojanSpy.MSIL.NANOCORE.SMQ.hp
EmsisoftGen:Trojan.Mardom.MN.18 (B)
IkarusTrojan.Inject
JiangminBackdoor.MSIL.bwkr
AviraTR/AD.Nanocore.kdw
Antiy-AVLTrojan[Backdoor]/MSIL.Noancooe
Kingsoftmalware.kb.c.1000
XcitiumMalware@#2oxjese3n9yx8
MicrosoftBackdoor:MSIL/Noancooe.A
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
GDataGen:Trojan.Mardom.MN.18
GoogleDetected
AhnLab-V3Worm/Win32.IRCBot.C143161
ALYacGen:Trojan.Mardom.MN.18
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.MSIL.NANOCORE.SMQ.hp
RisingBackdoor.Nanocore!8.F894 (CLOUD)
YandexTrojan.Kryptik!2h2B+TEFtxg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73691366.susgen
FortinetMSIL/GenKryptik.DQPR!tr
BitDefenderThetaGen:NN.ZemsilF.36744.UmW@a8Ml62qi
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Spyware.BlackShadesNET?

Spyware.BlackShadesNET removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment