Virus

Virus:Win32/Shodi.C removal guide

Malware Removal

The Virus:Win32/Shodi.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Shodi.C virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Virus:Win32/Shodi.C?


File Info:

name: 98A1DFD83D459F415C29.mlw
path: /opt/CAPEv2/storage/binaries/2bf31902b227f31ed9045dae9c8ec5652eba71b967df38be040a678fa6f6a7fa
crc32: EDBE5157
md5: 98a1dfd83d459f415c29fa7a9bffdc8f
sha1: 9b106aebc1cea15ed1a48d9e66656ca84f314e45
sha256: 2bf31902b227f31ed9045dae9c8ec5652eba71b967df38be040a678fa6f6a7fa
sha512: d8593599104b0770d119736ddb63abd665970c5ce5a8e26e972f99b283de118583bb08f98e5edf20ae32e1d8a9c262753535a049d1c61566ef1de42833d70363
ssdeep: 3072:QoW4d9jto7kxJT4GopSDoYXLQK7pSDoYXLQKWgPttoCyy4yqfN78hd:QSdwkBewJw0gPttR14nId
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115146B03B6A540E9C00AD1B85B859636EEB6B4910B347ADF07905B7A3F76FE06B7D310
sha3_384: b3e7f964b2c45f8eeb2b1b8f7dcf8407e639d866e3a7ec164080b8e1a119b2bf302c85890142c701a87a2949cf5425ed
ep_bytes: 558bec6aff681892400068d461400064
timestamp: 2004-01-04 07:51:41

Version Info:

0: [No Data]

Virus:Win32/Shodi.C also known as:

Elasticmalicious (high confidence)
DrWebWin32.HLLP.Shohdi
MicroWorld-eScanTrojan.GenericKD.66703974
FireEyeGeneric.mg.98a1dfd83d459f41
ALYacTrojan.GenericKD.66703974
MalwarebytesMalware.AI.158774251
ZillyaVirus.Shodi.Win32.6
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( 00565c3a1 )
K7AntiVirusVirus ( 00565c3a1 )
BitDefenderThetaGen:NN.ZexaF.36196.mqZ@a8!z@LhG
VirITWin32.Shodi.B
CyrenW32/Agent.FQP.gen!Eldorado
SymantecW32.Shodi.C
ESET-NOD32Win32/HLLP.Shodi.C
APEXMalicious
ClamAVWin.Virus.Shodi-10002307-0
KasperskyVirus.Win32.HLLP.Shodi.c
BitDefenderTrojan.GenericKD.66703974
NANO-AntivirusVirus.Win32.HLLP.gjnq
AvastWin32:ShodiD
SophosW32/Shodi-I
F-SecureMalware.W32/Shodi.C
VIPRETrojan.GenericKD.66703974
McAfee-GW-EditionBehavesLike.Win32.Shodi.dh
EmsisoftTrojan.GenericKD.66703974 (B)
IkarusVirus.Win32.HLLP.Shodi.C
GDataTrojan.GenericKD.66703974
JiangminWin32/HLLP.Shodi.d
AviraW32/Shodi.C
Antiy-AVLVirus/Win32.Shodi.a
XcitiumWin32.HLLP.Shodi.C@3pzt
ArcabitTrojan.Generic.D3F9D266
ZoneAlarmVirus.Win32.HLLP.Shodi.c
MicrosoftVirus:Win32/Shodi.C
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Shodi.C505612
Acronissuspicious
McAfeeW32/Shodi.worm.d
MAXmalware (ai score=80)
Cylanceunsafe
PandaW32/HLLP.Shodi.C
RisingTrojan.Generic@AI.87 (RDML:t283YlBkIzxtwAVdEmqapw)
YandexTrojan.GenAsa!uIynsBP074A
SentinelOneStatic AI – Suspicious PE
FortinetW32/Shodi.C
AVGWin32:ShodiD
Cybereasonmalicious.bc1cea
DeepInstinctMALICIOUS

How to remove Virus:Win32/Shodi.C?

Virus:Win32/Shodi.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment