Worm

Win32.Worm.Shodi.C information

Malware Removal

The Win32.Worm.Shodi.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Shodi.C virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid

How to determine Win32.Worm.Shodi.C?


File Info:

name: 564814B8473CE30435DE.mlw
path: /opt/CAPEv2/storage/binaries/9f364bf4087ffd9fd7493f5f06baa603a7935d60a117a8f34cb9a5cd04e302e0
crc32: 9AE1DA4D
md5: 564814b8473ce30435de0c923e9337b3
sha1: 362a58448ead11cd3d3f490c11038681f2956eaf
sha256: 9f364bf4087ffd9fd7493f5f06baa603a7935d60a117a8f34cb9a5cd04e302e0
sha512: 6f3a4fb51c22e51ab5d072649fb61e787526667b12aa51b3b4cc44dac6ebf183645f2f88830f49d316d2559715450ebe33654f715464e648904914aae72ecc32
ssdeep: 3072:QoW4d9Io7JaFkpSDoYXLQKWgPttfDc6RKUKwXgeslDRoNRN:QSdZ+kw0gPttbNueaRoTN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1046D1F75914AB5D05F80B0D21A5672A563BC264FE057EB4380DD793A33BE0AB3AB43
sha3_384: 70af579f3757b88f043258e5cf8c1c7a9e4e6e328664987fc06a5d26a9e370caae54e791f8f041b74a9065224a824d32
ep_bytes: 558bec6aff681892400068d461400064
timestamp: 2004-01-04 07:51:41

Version Info:

0: [No Data]

Win32.Worm.Shodi.C also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Worm.Shodi.C
ClamAVWin.Virus.Shodi-10013707-0
FireEyeGeneric.mg.564814b8473ce304
SkyhighBehavesLike.Win32.Shodi.ch
McAfeeW32/Shodi.worm.d
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 00565c3a1 )
K7GWVirus ( 00565c3a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.lqZ@a8!z@LhG
VirITWin32.Shodi.B
SymantecW32.Shodi.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/HLLP.Shodi.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.HLLP.Shodi.c
BitDefenderWin32.Worm.Shodi.C
NANO-AntivirusVirus.Win32.HLLP.gjnq
AvastWin32:ShodiD
TencentVirus.Win32.Shodi.ka
EmsisoftWin32.Worm.Shodi.C (B)
F-SecureMalware.W32/Shodi.C
DrWebWin32.HLLP.Shohdi
VIPREWin32.Worm.Shodi.C
SophosW32/Shodi-I
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Shodi.C
JiangminWin32/HLLP.Shodi.d
GoogleDetected
AviraW32/Shodi.C
MAXmalware (ai score=87)
Antiy-AVLVirus/Win32.Shodi.a
XcitiumWin32.HLLP.Shodi.C@3pzt
ArcabitWin32.Worm.Shodi.C
ZoneAlarmVirus.Win32.HLLP.Shodi.c
MicrosoftVirus:Win32/Shodi.C
VaristW32/Thier.WWSJ-0001
AhnLab-V3Malware/Win32.Shodi.C505612
ALYacWin32.Worm.Shodi.C
Cylanceunsafe
PandaW32/HLLP.Shodi.C
RisingWin32.Shodi.a (CLASSIC)
YandexTrojan.GenAsa!uIynsBP074A
IkarusVirus.Win32.HLLP.Shodi.C
MaxSecureVirus.W32.Shodi.C
FortinetW32/Shodi.C
AVGWin32:ShodiD
Cybereasonmalicious.48ead1
DeepInstinctMALICIOUS

How to remove Win32.Worm.Shodi.C?

Win32.Worm.Shodi.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment