Trojan

Trojan.Delshad information

Malware Removal

The Trojan.Delshad is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Delshad virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Delshad?


File Info:

crc32: 3CA7CECE
md5: b96d7569d68440a9d6fc2f33d8adcae7
name: dmx777.exe
sha1: 6379a05b3645203df1ec815ee5e81e7aa98088e9
sha256: 79afaaa7fa75217d4a771f7f83c5ef4ec7b3dcd9e85deb6767933524ef6b9ee7
sha512: 3a69754f4884fd9a47e25f2067fcb4e2afbeeedfe3286ed6e1daeacffbf98692bf84ee6abdfcef83d5b7d7192b34c7652adfea6cd67c96c3556febf8d9d7f33e
ssdeep: 6144:pS6MrZzRgkkZ2rorInJp3cSaAQTnoo/75NZ:pkzdk0s0nXc9AQTnoolb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (c) Omnesys Technologies, Inc.
InternalName: 931667
FileVersion: 3.8.7.6
CompanyName: Omnesys Technologies, Inc.
LegalTrademarks: Copyright (c) Omnesys Technologies, Inc.
ProductName: 931667
ProductVersion: 3.8.7.6
FileDescription: Translation Hand Truncatin Counterrotating Clients Services
Translation: 0x0409 0x04b0

Trojan.Delshad also known as:

MicroWorld-eScanTrojan.GenericKD.42074338
FireEyeGeneric.mg.b96d7569d68440a9
CAT-QuickHealTrojan.Delshad
McAfeeRDN/Generic.tfr
MalwarebytesTrojan.MalPack.UPX
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0055c8711 )
BitDefenderTrojan.GenericKD.42074338
K7GWTrojan ( 0055c8711 )
Cybereasonmalicious.b36452
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.32519.smKfaO2hz1di
CyrenW32/Trojan.YUGK-9327
SymantecRansom.Crysis
APEXMalicious
KasperskyTrojan.Win32.DelShad.brv
RisingTrojan.Generic@ML.89 (RDML:232FsyrGIvfjaKkjezXJTw)
Ad-AwareTrojan.GenericKD.42074338
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Crysis.gub
DrWebTrojan.Encoder.3953
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.moderate.ml.score
IkarusTrojan.Win32.Crypt
JiangminTrojan.DelShad.lb
WebrootW32.Trojan.GenKD
AviraTR/AD.Crysis.gub
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.DelShad
MicrosoftTrojan:Win32/Tiggre!rfn
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D28200E2
ZoneAlarmTrojan.Win32.DelShad.brv
GDataTrojan.GenericKD.42074338
VBA32Trojan.DelShad
ALYacTrojan.Ransom.Crysis
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GYYR
TrendMicro-HouseCallTROJ_GEN.R03BC0PL219
FortinetW32/Kryptik.GVSM!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.ddc

How to remove Trojan.Delshad?

Trojan.Delshad removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment