Trojan

Trojan.Win32.DelShad.fev malicious file

Malware Removal

The Trojan.Win32.DelShad.fev is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.DelShad.fev virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.DelShad.fev?


File Info:

crc32: 982228F7
md5: 69b2e5d45b9eb9b7d342f6f580dd6ba8
name: upload_file
sha1: 6005c62f68ab4541e4d285d5e20877904b08fc48
sha256: ec9b412e9a6e0da1a21c01158c4c8313b61b033f58d16d913d72229794069d18
sha512: 511d47ebbc55fa612ef8755446b835079bb6c09c22fe6987ed9170a1efabc2f5ada0e9f801899e5f315401aa8d4408e0883f34d8d4fbd6dcf944a6b99e0af430
ssdeep: 1536:7D7B2MPvShDjlmbOTMYggRixqRal8fBclKrzgDG5fWEQF2z:PXitjlCTY0SgyhWEks
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.DelShad.fev also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.Imps.1
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXAA-FA!69B2E5D45B9E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Imps.4!c
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Heur.Ransom.Imps.1
K7GWTrojan ( 0056994f1 )
K7AntiVirusTrojan ( 0056994f1 )
ArcabitTrojan.Ransom.Imps.1
BitDefenderThetaAI:Packer.665CB24E1E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.WastedLocker.A
APEXMalicious
AvastWin32:Dh-A [Heur]
KasperskyTrojan.Win32.DelShad.fev
AlibabaRansom:Win32/WastedLocker.275d3f11
RisingRansom.WastedLocker!8.11D3E (TFE:1:Gu6RSxNvyNB)
Ad-AwareGen:Heur.Ransom.Imps.1
EmsisoftGen:Heur.Ransom.Imps.1 (B)
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.69b2e5d45b9eb9b7
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
MicrosoftTrojan:Win32/Ymacco.AADC
ZoneAlarmTrojan.Win32.DelShad.fev
GDataGen:Heur.Ransom.Imps.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransom.C4170354
VBA32BScope.Trojan.DelShad
ALYacGen:Heur.Ransom.Imps.1
MAXmalware (ai score=80)
MalwarebytesRansom.BinADS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H09JV20
TencentWin32.Trojan.Filecoder.Wrgs
IkarusTrojan-Ransom.WastedLocker
eGambitUnsafe.AI_Score_98%
FortinetW32/Filecoder_WastedLocker.A!tr
AVGWin32:Dh-A [Heur]
Cybereasonmalicious.45b9eb
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.IM.1dd

How to remove Trojan.Win32.DelShad.fev?

Trojan.Win32.DelShad.fev removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment