Trojan

Trojan.DelshadRI.S13221298 removal instruction

Malware Removal

The Trojan.DelshadRI.S13221298 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DelshadRI.S13221298 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Creates an autorun.inf file
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Clears Windows events or logs
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.DelshadRI.S13221298?


File Info:

crc32: 8B8079C3
md5: f05df52a73ea28f25d0a85f927f2444a
name: F05DF52A73EA28F25D0A85F927F2444A.mlw
sha1: a5c00571f42bad2f17db4d4032b07318abc6f7f1
sha256: 1e2335fef46f7320069623fff6702acb41c2877aff5fec83d94a561af37c3c7a
sha512: 0b2a3a0bde6fcc23565ccdb1df49727930ad53345f91a3450455d0e8fb431a59af74a169d8c6ae2195afc340d7fde42969638f5d4de5501d1f75737be625e0b2
ssdeep: 12288:cPJ4U0TYQivI2qZ7aSgLwkFVpzUvest4ZEbjJLuYJVoM7:JzTYVQ2qZ7aSgLwuVfstRJLHYM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.DelshadRI.S13221298 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055a9531 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.34694
CynetMalicious (score: 100)
CAT-QuickHealTrojan.DelshadRI.S13221298
ALYacGeneric.Ransom.MedusaLocker.942644D7
CylanceUnsafe
ZillyaTrojan.DelShad.Win32.481
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaRansom:Win32/MedusaLocker.69347fa6
K7GWTrojan ( 0055a9531 )
Cybereasonmalicious.a73ea2
CyrenW32/Ransom.OB.gen!Eldorado
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.MedusaLocker.C
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Medusalocker-9811271-0
KasperskyTrojan-Ransom.Win32.Medusa.aj
BitDefenderGeneric.Ransom.MedusaLocker.942644D7
NANO-AntivirusTrojan.Win32.Filecoder.hjdojw
ViRobotTrojan.Win32.Medusa.694784
MicroWorld-eScanGeneric.Ransom.MedusaLocker.942644D7
TencentMalware.Win32.Gencirc.10cdcb68
Ad-AwareGeneric.Ransom.MedusaLocker.942644D7
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34050.QuW@aK8T6Ili
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MEDUSALOCKER.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.f05df52a73ea28f2
EmsisoftGeneric.Ransom.MedusaLocker.942644D7 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.DelShad.vv
AviraTR/AD.MedusaRansom.yvkui
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.304C35A
MicrosoftRansom:Win32/MedusaLocker.A!MTB
GridinsoftRansom.Win32.Gen.ko!s1
ZoneAlarmTrojan-Ransom.Win32.Medusa.aj
GDataWin32.Trojan-Ransom.Filecoder.BO
TACHYONRansom/W32.MedusaLocker.694784
AhnLab-V3Malware/Win32.RL_Generic.R335910
McAfeeGenericRXKP-XE!F05DF52A73EA
MAXmalware (ai score=87)
VBA32Trojan.DelShad
MalwarebytesRansom.Medusa
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.MEDUSALOCKER.SMTH
RisingRansom.MedusaLocker!1.C21A (CLASSIC)
YandexTrojan.Filecoder!IKimDDCJuYs
IkarusTrojan-Ransom.Medusalocker
MaxSecureTrojan.Malware.88792205.susgen
FortinetW32/Filecoder.NYA!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.MedusaLocker.HwoCrB8B

How to remove Trojan.DelshadRI.S13221298?

Trojan.DelshadRI.S13221298 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment