Worm

Win32.Worm.Shodi.C malicious file

Malware Removal

The Win32.Worm.Shodi.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Shodi.C virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid

How to determine Win32.Worm.Shodi.C?


File Info:

name: 379F1F6C7990C2621CC4.mlw
path: /opt/CAPEv2/storage/binaries/432e7e1fc329a436c64fe0281ae2e3aa0fb84b1cde70cbb80aa90d79acb20480
crc32: 3780ADF9
md5: 379f1f6c7990c2621cc4ab354527c793
sha1: aa7bba558a4cd6fd13abe79a0b2032a0f41f984f
sha256: 432e7e1fc329a436c64fe0281ae2e3aa0fb84b1cde70cbb80aa90d79acb20480
sha512: adee68e1ae3c6e49cc3b623130322e4fc77a57165ca1d23535a5e102f6919d4a3064f032ff39c25f265748096180050609f03fc5d838dd847e325385c6a24d29
ssdeep: 6144:QSdZ1wHYrIOXsqmWzJrdc6GJRQUWGUA9PRWLiFSbE56FORF4:Pm2lWRPWhA9PRWg9I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAC43A02B7E99034F5F31B31AFB592655A7BBC629E35C64F2384191D0DB0A80EA35B73
sha3_384: e744106f9d4d6b1dc1dd6c58c9544aff3c6a487a0ccdd559b1ab46c46c49e09fbbeecaa4e040272a1cbef1d01d3a6301
ep_bytes: 558bec6aff681892400068d461400064
timestamp: 2004-01-04 07:51:41

Version Info:

0: [No Data]

Win32.Worm.Shodi.C also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.Shodi.C
FireEyeGeneric.mg.379f1f6c7990c262
SkyhighBehavesLike.Win32.Shodi.hh
McAfeeW32/Shodi.worm.d
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Worm.Shodi.C
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 00565c3a1 )
K7GWVirus ( 00565c3a1 )
Cybereasonmalicious.58a4cd
ArcabitWin32.Worm.Shodi.C
VirITWin32.Shodi.B
SymantecW32.Shodi.C
tehtrisGeneric.Malware
ESET-NOD32Win32/HLLP.Shodi.C
APEXMalicious
ClamAVWin.Virus.Shodi-10013707-0
KasperskyVirus.Win32.HLLP.Shodi.c
BitDefenderWin32.Worm.Shodi.C
NANO-AntivirusVirus.Win32.HLLP.gjnq
AvastWin32:ShodiD
TencentVirus.Win32.Shodi.ka
EmsisoftWin32.Worm.Shodi.C (B)
F-SecureMalware.W32/Shodi.C
DrWebWin32.HLLP.Shohdi
ZillyaVirus.Shodi.Win32.6
TrendMicroPE_SHODI.T
SophosW32/Shodi-I
IkarusVirus.Win32.HLLP.Shodi.C
JiangminWin32/HLLP.Shodi.d
GoogleDetected
AviraW32/Shodi.C
VaristW32/Thier.WWSJ-0001
Antiy-AVLVirus/Win32.Shodi.a
XcitiumWin32.HLLP.Shodi.C@3pzt
MicrosoftVirus:Win32/Shodi.C
ZoneAlarmVirus.Win32.HLLP.Shodi.c
GDataWin32.Worm.Shodi.C
CynetMalicious (score: 100)
AhnLab-V3Win32/HLLP.Shodi.X1346
ALYacWin32.Worm.Shodi.C
MAXmalware (ai score=86)
PandaW32/HLLP.Shodi.C
TrendMicro-HouseCallPE_SHODI.T
RisingWin32.Shodi.a (CLASSIC)
YandexTrojan.GenAsa!uIynsBP074A
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Shodi.C
FortinetW32/Shodi.C
AVGWin32:ShodiD
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32.Worm.Shodi.C?

Win32.Worm.Shodi.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment