Malware

How to remove “Sf:ShellCode-R [Trj]”?

Malware Removal

The Sf:ShellCode-R [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Sf:ShellCode-R [Trj] virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Sf:ShellCode-R [Trj]?


File Info:

crc32: 9696678C
md5: a796fe63b61f7522f2e2fd3f22dcb97a
name: A796FE63B61F7522F2E2FD3F22DCB97A.mlw
sha1: 0aebb6d91d713643386fbd588253dc005c4b4719
sha256: 1a571f87f038cb604d7c5c71aeb4de30b92f011abff1b29d44813bfbb339d87c
sha512: a9b60d3dc906faf5bbfe19e665c2c5f34455e4c377dbff116977bc39d36d6530e4c7ae0ee8ece9bf65313375f09055f68d02dec6cc25a3fabe3c132f1c24da55
ssdeep: 6144:GJ4WTBJJibYaFvqcMAEuT7QSW8vU8Jy+84+Mkoqts5H+8ImaYW3PBuqzvCA9St:G4WTrJibYaFUAEuXTWzr+84+BoBH+dvu
type: MS-DOS executable

Version Info:

0: [No Data]

Sf:ShellCode-R [Trj] also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 004b8cd91 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.3001
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Dreidel.smX@xWpBTxb
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.202513
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanPSW:Win32/FakeAlert.1bdcaaf8
K7GWSpyware ( 004b8cd91 )
Cybereasonmalicious.3b61f7
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Zbot.AAN
APEXMalicious
AvastSf:ShellCode-R [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Dreidel.smX@xWpBTxb
NANO-AntivirusTrojan.Win32.Panda.bbwibo
MicroWorld-eScanGen:Heur.Mint.Dreidel.smX@xWpBTxb
TencentMalware.Win32.Gencirc.114933a1
Ad-AwareGen:Heur.Mint.Dreidel.smX@xWpBTxb
SophosML/PE-A + Mal/Zbot-HX
ComodoTrojWare.Win32.Spy.ZBot.AAU@4wkkp5
BitDefenderThetaGen:NN.ZexaF.34236.smX@aWpBTxb
VIPRETrojan.Win32.Zbot.aka (v)
TrendMicroTROJ_AGENT_049460.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.a796fe63b61f7522
EmsisoftGen:Heur.Mint.Dreidel.smX@xWpBTxb (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.amzzv
AviraTR/Hijacker.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1B7D08
MicrosoftPWS:Win32/Zbot!GO
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
GDataGen:Heur.Mint.Dreidel.smX@xWpBTxb
AhnLab-V3Spyware/Win32.Zbot.R41044
Acronissuspicious
McAfeePWS-Zbot.gen.aov
MAXmalware (ai score=100)
VBA32SScope.Trojan.FakeAV.01110
PandaGeneric Malware
TrendMicro-HouseCallTROJ_AGENT_049460.TOMB
RisingSpyware.Zbot!1.648A (CLASSIC)
YandexTrojan.GenAsa!Mr/4JANihH4
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.AAN!tr
AVGSf:ShellCode-R [Trj]
Paloaltogeneric.ml

How to remove Sf:ShellCode-R [Trj]?

Sf:ShellCode-R [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment