Trojan

What is “Trojan.Win32.Shelma.brvv”?

Malware Removal

The Trojan.Win32.Shelma.brvv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Shelma.brvv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Trojan.Win32.Shelma.brvv?


File Info:

name: 5806674DA3CE18688869.mlw
path: /opt/CAPEv2/storage/binaries/3afb0a2165bc57ab9c7ab56284e7430bda704f6974d42317c5f5cf05ec2186ed
crc32: ECD355D4
md5: 5806674da3ce186888691b6322f1c3e9
sha1: 70b0d27c324bdf635327b0ec6210af66e332689e
sha256: 3afb0a2165bc57ab9c7ab56284e7430bda704f6974d42317c5f5cf05ec2186ed
sha512: d3d273ec689f6bcd48682fffe88f030140b509d730cdfd29ab355e6a3534bddb4d0607daf469b17b0689fbeff805ddd119f92cfffc31765be56cbb15bca92ba0
ssdeep: 196608:/72FZW9onJ5hrZERtktPOKjPob56WlDv:C3W9c5hlERkPOBXD
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1C776331A326158E9F5B6903644810834D637B93A4729C72F4BBC536A7FB36E1AD3DF02
sha3_384: 237867d717ef2de0f62fcd26beafad45b1eda193d3f587c8c0c7ab4ab09851eaff405bff84f4e06437c4c7650e4ce60e
ep_bytes: 4883ec28e8f70400004883c428e97afe
timestamp: 2021-08-01 04:39:46

Version Info:

0: [No Data]

Trojan.Win32.Shelma.brvv also known as:

LionicTrojan.Win32.Shelma.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38212279
ALYacTrojan.GenericKD.38212279
BitDefenderTrojan.GenericKD.38212279
CyrenW64/Bulz.BI.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Shelma.brvv
AlibabaExploit:Win32/Shelma.187e049f
AvastFileRepMalware
TencentWin32.Trojan.Shelma.Stuc
Ad-AwareTrojan.GenericKD.38212279
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DLA21
McAfee-GW-EditionBehavesLike.Win64.Ransom.vc
FireEyeTrojan.GenericKD.38212279
EmsisoftTrojan.GenericKD.38212279 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1145663
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.34493BB
MicrosoftExploit:Python/Leivion.B
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D24712B7
GDataMSIL.Backdoor.Rozena.TTL518
CynetMalicious (score: 100)
McAfeeArtemis!5806674DA3CE
TrendMicro-HouseCallTROJ_GEN.R002C0DLA21
FortinetPossibleThreat.PALLAS.H
AVGFileRepMalware
PandaTrj/CI.A

How to remove Trojan.Win32.Shelma.brvv?

Trojan.Win32.Shelma.brvv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment