Malware

UDS:Exploit.Win32.Shellcode (file analysis)

Malware Removal

The UDS:Exploit.Win32.Shellcode is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Exploit.Win32.Shellcode virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system

How to determine UDS:Exploit.Win32.Shellcode?


File Info:

crc32: 7DA8C18F
md5: 18bedebe0076d0704cb24ae93926b9dc
name: 18BEDEBE0076D0704CB24AE93926B9DC.mlw
sha1: d929aa0f8bc0f03236a38096c8c1e64f0e766b35
sha256: dcb02549ffe1d2212dbddc97bf48fc57965ca634ff30665cdeb085e60ae73690
sha512: 08af9b8e86683803272dbba205e78622cc2dc38ae8ee971a633ac26a9615919d07bfd9f27fac85aa876e862ae384eba0721f54dc09854d60ced94546a0d967fb
ssdeep: 6144:oTw0ao+rpQX2vR4l1EDZF7pLdzykaAbaj/fh7QszytjRLiXmuavmzGZYY97e+r:10at4Po/tWDhcjt9oMmzyYYRe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.5.8.28
FileVerus: 1.0.2.27
Translations: 0x0126 0x0294

UDS:Exploit.Win32.Shellcode also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003e58dd1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!18BEDEBE0076
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 003e58dd1 )
Cybereasonmalicious.f8bc0f
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Exploit.Win32.Shellcode.gen
SophosML/PE-A
BitDefenderThetaAI:Packer.B113752320
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.18bedebe0076d070
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Glupteba.PH!MTB
ZoneAlarmUDS:DangerousObject.Multi.Generic
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazqdQ/NDXYpyk/pLPW/4BN6l)
IkarusTrojan-Banker.UrSnif
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware

How to remove UDS:Exploit.Win32.Shellcode?

UDS:Exploit.Win32.Shellcode removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment