Crack Trojan

How to remove “Trojan.ShellCode.Patched”?

Malware Removal

The Trojan.ShellCode.Patched is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ShellCode.Patched virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan.ShellCode.Patched?


File Info:

name: F827A0FD91F0A410CDB4.mlw
path: /opt/CAPEv2/storage/binaries/f8a1f24ec0918465fa0a78f33de9d87ea3a767c06216651db8aac854ab50d569
crc32: 9A20E6F9
md5: f827a0fd91f0a410cdb44f1e52a0ea48
sha1: ded3ae387c8bd29b7c07ed0e07b1bfa78d2c9d80
sha256: f8a1f24ec0918465fa0a78f33de9d87ea3a767c06216651db8aac854ab50d569
sha512: b223b3ea2b5cd2a30e24d18cfbbda3f48d9a19e3d40a76949de3ce98d63b36c52659d7d15b8e4f0a4e500f8d3dab19380072e6c89ff3f4521acdf7c6f7b4e059
ssdeep: 6144:i4VU52dn+OAdUV0RzCbXkThYrK9qqUtmtime:i4K2B+Ob2y0NXIn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10F346C52A648A0B1CA623174567AFF369D7EFC70871252C7B7F05DAB78A01C0B63D31A
sha3_384: f0b7260fc0134009625f273f513a0b261f6ad6a44f18197fd7b4787dc02aeb191c82347758d16ab2e5ef2fbdef792754
ep_bytes: b8cb699f94dad1d97424f45e2bc9b167
timestamp: 2102-04-20 00:53:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Command Processor
FileVersion: 10.0.19041.746 (WinBuild.160101.0800)
InternalName: cmd
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Cmd.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.746
Translation: 0x0409 0x04b0

Trojan.ShellCode.Patched also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.ShellCode.Marte.3.850F03E2
FireEyeDeepScan:Generic.ShellCode.Marte.3.850F03E2
McAfeeRDN/Generic BackDoor
MalwarebytesTrojan.ShellCode.Patched
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 00480e401 )
AlibabaTrojan:Win32/Meterpreter.40340746
K7GWTrojan ( 00480e401 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Rozena.DZ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Rozena.DO
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.ShellCode.Marte.3.850F03E2
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Qcnw
EmsisoftDeepScan:Generic.ShellCode.Marte.3.850F03E2 (B)
VIPREDeepScan:Generic.ShellCode.Marte.3.850F03E2
McAfee-GW-EditionRDN/Generic BackDoor
SophosATK/Swrort-N
SentinelOneStatic AI – Suspicious PE
GDataDeepScan:Generic.ShellCode.Marte.3.850F03E2
ArcabitDeepScan:Generic.ShellCode.Marte.3.850F03E2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Meterpreter.A
GoogleDetected
AhnLab-V3Backdoor/Win.Swrort.C4521918
ALYacDeepScan:Generic.ShellCode.Marte.3.850F03E2
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Rozena!8.6D (CLOUD)
IkarusTrojan.Win32.Rozena
FortinetW32/Rozena.ED!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.d91f0a
DeepInstinctMALICIOUS

How to remove Trojan.ShellCode.Patched?

Trojan.ShellCode.Patched removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment