Malware

Should I remove “ATK/Shellter-H”?

Malware Removal

The ATK/Shellter-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ATK/Shellter-H virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ATK/Shellter-H?


File Info:

crc32: EB50D195
md5: f5a2ab56c52caac29c4ba76cd78cba15
name: F5A2AB56C52CAAC29C4BA76CD78CBA15.mlw
sha1: b55cd93cad54f80e3e43c4e7fe4e314b37715c3c
sha256: e645af2706ed0d6c6b3cd1a05f4d1aced81aef6643935752322ae32642735add
sha512: 5465dbbc4b86e3b8c49dc95daf1035fb4e2c17e78b9c7a0520064fa1da4c5841fa7037f533b570d8744e603678a1607548671ade8b713c47103fda63b691052f
ssdeep: 6144:NGkTsYW02QnZlmR75Yi2X3IQCn3fjA9VZFzUxXOdy/KkicWM+5nXwB:NGf026ZlmR70Y/k9VS+LPMR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2016 Igor Pavlov
InternalName: 7zFM
FileVersion: 16.02
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 16.02
FileDescription: 7-Zip File Manager
OriginalFilename: 7zFM.exe
Translation: 0x0409 0x04b0

ATK/Shellter-H also known as:

ALYacTrojan.BackSwap.A
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Bulta.aea66b87
Cybereasonmalicious.6c52ca
SymantecTrojan.Backswap
ESET-NOD32Win32/BackSwap.A
APEXMalicious
AvastWin32:Banker-NBQ [Trj]
ClamAVWin.Trojan.Backswap-6564636-0
BitDefenderTrojan.Patched.SAP.Gen.2
MicroWorld-eScanTrojan.Patched.SAP.Gen.2
TencentWin32.Trojan.Patched.Edxa
Ad-AwareTrojan.Patched.SAP.Gen.2
SophosATK/Shellter-H
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
FireEyeTrojan.Patched.SAP.Gen.2
EmsisoftTrojan.Patched.SAP.Gen.2 (B)
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Bulta!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Patched.SAP.Gen.2
McAfeeArtemis!F5A2AB56C52C
MAXmalware (ai score=94)
VBA32Trojan.Tiggre
PandaTrj/CI.A
RisingTrojan.ClipBanker!8.5FB (CLOUD)
YandexTrojan.Cossta!xMBzI9YqC0Q
IkarusTrojan-Banker.Backswap
FortinetW32/BackSwap.A!tr
AVGWin32:Banker-NBQ [Trj]

How to remove ATK/Shellter-H?

ATK/Shellter-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment