Worm

Win32.Worm.Shodi.C malicious file

Malware Removal

The Win32.Worm.Shodi.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Shodi.C virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Win32.Worm.Shodi.C?


File Info:

name: 4E9D45B1B8CCC545D481.mlw
path: /opt/CAPEv2/storage/binaries/8f8db1acd6b5240d3e671ee131a7f01594057b8413f933110723685db22d5263
crc32: 2613E39F
md5: 4e9d45b1b8ccc545d481fb11128f3bdd
sha1: d5f735faac1a18af19646b0c59047b08d17f0a3b
sha256: 8f8db1acd6b5240d3e671ee131a7f01594057b8413f933110723685db22d5263
sha512: 0ac14bdba9383db2aff6f1d4a62f8cb259cc6ac77e0fb7cc3877557b3e2e9d57165201873ae058bab74adbb3568937fc493c2f6eef9a781a896ea3c11b1b60f9
ssdeep: 6144:QSdZI+ZxehRyo7/79+x+qOBlyO1UdWmxLOkA:G+Z42xOBlyO1UdWXkA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7746B5577E000A4E077D575C5A60576E6B6BC261B609FEF0380E06A0E37BE0AE3DF62
sha3_384: 6e160efbb5a327332aabc6f1dcd05db880743cc3af63258217abccbfc3000f4a729062c67b080e460b8479022961dd4d
ep_bytes: 558bec6aff681892400068d461400064
timestamp: 2004-01-04 07:51:41

Version Info:

0: [No Data]

Win32.Worm.Shodi.C also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.Shodi.C
ClamAVWin.Virus.Shodi-10013707-0
FireEyeGeneric.mg.4e9d45b1b8ccc545
SkyhighBehavesLike.Win32.Shodi.fh
McAfeeW32/Shodi.worm.d
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Worm.Shodi.C
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 00565c3a1 )
K7GWVirus ( 00565c3a1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITWin32.Shodi.B
SymantecW32.Shodi.C
tehtrisGeneric.Malware
ESET-NOD32Win32/HLLP.Shodi.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.HLLP.Shodi.c
BitDefenderWin32.Worm.Shodi.C
NANO-AntivirusVirus.Win32.HLLP.gjnq
AvastWin32:ShodiD
TencentVirus.Win32.Shodi.ka
SophosW32/Shodi-I
F-SecureMalware.W32/Shodi.C
DrWebWin32.HLLP.Shohdi
ZillyaVirus.Shodi.Win32.6
TrendMicroPE_SHODI.T
EmsisoftWin32.Worm.Shodi.C (B)
IkarusVirus.Win32.HLLP.Shodi.C
GDataWin32.Worm.Shodi.C
JiangminWin32/HLLP.Shodi.d
GoogleDetected
AviraW32/Shodi.C
Antiy-AVLVirus/Win32.Shodi.a
Kingsoftmalware.kb.a.931
XcitiumWin32.HLLP.Shodi.C@3pzt
ArcabitWin32.Worm.Shodi.C
ZoneAlarmVirus.Win32.HLLP.Shodi.c
MicrosoftVirus:Win32/Shodi.C
VaristW32/Thier.WWSJ-0001
AhnLab-V3Win32/HLLP.Shodi.X1346
ALYacWin32.Worm.Shodi.C
MAXmalware (ai score=83)
Cylanceunsafe
PandaW32/HLLP.Shodi.C
TrendMicro-HouseCallPE_SHODI.T
RisingWin32.Shodi.a (CLASSIC)
YandexTrojan.GenAsa!uIynsBP074A
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Shodi.C
FortinetW32/Shodi.C
AVGWin32:ShodiD
Cybereasonmalicious.aac1a1
DeepInstinctMALICIOUS

How to remove Win32.Worm.Shodi.C?

Win32.Worm.Shodi.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment