Malware

What is “Win32/HLLP.Shodi.I”?

Malware Removal

The Win32/HLLP.Shodi.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HLLP.Shodi.I virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/HLLP.Shodi.I?


File Info:

name: EF913C6E8790C3B0BA82.mlw
path: /opt/CAPEv2/storage/binaries/141ca60d513613764e6f64b780c95bc320de21506cddc23d989138f231e1f40d
crc32: 5D4A0CD3
md5: ef913c6e8790c3b0ba828d341bd54ba7
sha1: bffa61f08446fc5c275fce068c9fbadf82d7d0b8
sha256: 141ca60d513613764e6f64b780c95bc320de21506cddc23d989138f231e1f40d
sha512: d00682b6c32daf69835faa644908d5e337709f7fa2d64ab01c0b0c585f552045c5736781c97cbf856885fa433761fb82c251e47e8f7b19cb533f38ca0e72d4dd
ssdeep: 49152:qaUasqc1bXsPNIULkmp1/j6AeXZG7wmpvGF1IP9z5WuHC4O8b8ITDnl27PLhb:qaPFSbXsPN5kiQaZ5c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129F5A12166D4CFE1D06F10B1ED66BAF5512BAD24CF554FCB6E803E1A35305D2AA32A0F
sha3_384: 664282ab62d28491d044417f4c3ce8f52b39e2edce78ece0f35bdd151eacb24c0f9128591a07fcc13c46ece47e4d8879
ep_bytes: 558bec6aff680031400068762b400064
timestamp: 2004-09-12 09:55:29

Version Info:

0: [No Data]

Win32/HLLP.Shodi.I also known as:

BkavW32.FamVT.SmallHQc.PE
AVGWin32:Shodi [Wrm]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.105403
FireEyeGeneric.mg.ef913c6e8790c3b0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Virut.wh
McAfeeW32/Shodi.a.worm.y
MalwarebytesGeneric.Malware/Suspicious
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 005005451 )
AlibabaTrojan:Win32/IRCbot.122c4f65
K7GWVirus ( 005005451 )
Cybereasonmalicious.e8790c
BitDefenderThetaGen:NN.ZexaF.36802.DtZ@aWxEhLmG
VirITWin32.Shohdi.A
SymantecW32.Shodi
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/HLLP.Shodi.I
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Shodi [Wrm]
ClamAVWin.Trojan.Agent-1388669
KasperskyHEUR:Trojan.Win32.IRCbot.gen
BitDefenderTrojan.GenericKDZ.105403
TencentVirus.Win32.Shodi.o
EmsisoftTrojan.GenericKDZ.105403 (B)
F-SecureMalware.W32/Shodi.I
VIPRETrojan.GenericKDZ.105403
TrendMicroPE_SHODI.Y
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.9V4P9U
WebrootW32.Shodi.I
VaristW32/Shodi.G.gen!Eldorado
AviraW32/Shodi.I
MAXmalware (ai score=81)
Antiy-AVLVirus/Win32.Shohdi.b
ArcabitTrojan.Generic.D19BBB
ZoneAlarmHEUR:Trojan.Win32.IRCbot.gen
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GoogleDetected
AhnLab-V3Win32/Shoudi.B.X1302
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.GenericKDZ.105403
TACHYONWorm/W32.Shoudi
Cylanceunsafe
PandaW32/Shodi.J
TrendMicro-HouseCallPE_SHODI.Y
RisingVirus.Shodi!1.9B9C (CLASSIC)
IkarusWin32.Shodi
MaxSecurevirus.shohdi.i
FortinetW32/Shodi.I
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/AAuto

How to remove Win32/HLLP.Shodi.I?

Win32/HLLP.Shodi.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment