Worm

Win32.Worm.Shodi.C removal guide

Malware Removal

The Win32.Worm.Shodi.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Shodi.C virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Win32.Worm.Shodi.C?


File Info:

name: 7321B3BB7E6FE488AA5F.mlw
path: /opt/CAPEv2/storage/binaries/4cc016a3e42914647691c532b6a0b5891f151217764df917e0e3c4a0da5347a8
crc32: A68C3F52
md5: 7321b3bb7e6fe488aa5f58376f18a85e
sha1: 86430d48570895465a56c0b5f518d8dd8453d48c
sha256: 4cc016a3e42914647691c532b6a0b5891f151217764df917e0e3c4a0da5347a8
sha512: d91f6d4a47751234fa15fd77d9d4ec8ab91dda437b7349fda2c2250f3b842b4b8edb231249aba0503e7d5052a7b24ca00c91c2564f4f1cac8989a6ea7e2afe15
ssdeep: 3072:QoW4d9Io76aFnkc6Q/UKsXPesz6RpCHok8kukm4gT/n51tkufuYth8FH:QSdZ1kZxehRyo7/79iufTtKFH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A449E2F7A9100B8D06FD174C79B1636A56374361BA05AEB0390D1B91E3BEE0BB3E745
sha3_384: 87f77a6e7c36257c89b26e9c8b5e29f002a7067e6d8352af8df58755c441602c1b48fe49e465842746f8afec0c9db679
ep_bytes: 558bec6aff681892400068d461400064
timestamp: 2004-01-04 07:51:41

Version Info:

0: [No Data]

Win32.Worm.Shodi.C also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Worm.Shodi.C
ClamAVWin.Virus.Shodi-10013707-0
FireEyeGeneric.mg.7321b3bb7e6fe488
SkyhighBehavesLike.Win32.Shodi.dh
McAfeeW32/Shodi.worm.d
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.Shodi.Win32.6
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 00565c3a1 )
K7GWVirus ( 00565c3a1 )
BitDefenderThetaGen:NN.ZexaF.36744.qqZ@a8!z@LhG
VirITWin32.Shodi.B
SymantecW32.Shodi.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/HLLP.Shodi.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.HLLP.Shodi.c
BitDefenderWin32.Worm.Shodi.C
NANO-AntivirusVirus.Win32.HLLP.gjnq
AvastWin32:ShodiD
TencentVirus.Win32.Shodi.ka
EmsisoftWin32.Worm.Shodi.C (B)
F-SecureMalware.W32/Shodi.C
DrWebWin32.HLLP.Shohdi
VIPREWin32.Worm.Shodi.C
TrendMicroTROJ_GEN.R03BC0CB924
SophosW32/Shodi-I
IkarusVirus.Win32.HLLP.Shodi.C
GDataWin32.Worm.Shodi.C
JiangminWin32/HLLP.Shodi.d
GoogleDetected
AviraW32/Shodi.C
Antiy-AVLVirus/Win32.Shodi.a
Kingsoftmalware.kb.a.859
XcitiumWin32.HLLP.Shodi.C@3pzt
ArcabitWin32.Worm.Shodi.C
ZoneAlarmVirus.Win32.HLLP.Shodi.c
MicrosoftVirus:Win32/Shodi.C
VaristW32/Thier.WWSJ-0001
AhnLab-V3Malware/Win32.Shodi.C505612
MAXmalware (ai score=80)
PandaW32/HLLP.Shodi.C
TrendMicro-HouseCallTROJ_GEN.R03BC0CB924
RisingWin32.Shodi.a (CLASSIC)
YandexTrojan.GenAsa!uIynsBP074A
SentinelOneStatic AI – Malicious PE
FortinetW32/Shodi.C
AVGWin32:ShodiD
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32.Worm.Shodi.C?

Win32.Worm.Shodi.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment