Trojan

How to remove “Trojan.Win32.Shelma.brwz”?

Malware Removal

The Trojan.Win32.Shelma.brwz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Shelma.brwz virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan.Win32.Shelma.brwz?


File Info:

name: 47D77980AD9AFBEBC15B.mlw
path: /opt/CAPEv2/storage/binaries/e10d006b259d69fbbeaf5a2b311ac3d415b51207826fe89b019669442d201cb7
crc32: C0A2378A
md5: 47d77980ad9afbebc15b3abde064cf33
sha1: 5fe86ea3cc84f59f0b1b1dd03a2fc9e100c6089b
sha256: e10d006b259d69fbbeaf5a2b311ac3d415b51207826fe89b019669442d201cb7
sha512: 85245e2958be863438932eebd5de47191499d99af04b49e9708054ae8812cb8d2cb95ec93ba512cee7c82ce4a636a396f5823aae86ca63d57b99b3b03e631155
ssdeep: 12288:jOmGug3IXZjYsvQU75vGovB8BeN8BbSkV28dA182ZBfrJc2n43r6PEV3yrCQuOGO:jo45YXUx9vBOVJAi2ZtmGPEV3YfDGEN
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1F90523D961D33C79DA920533AC6E41C316BD9EE2EE8B7774D1A172C904368B29FE4026
sha3_384: bdd1d788e33d39ae084a267292c8b19a2e3ef906938cf7c1b55ec87a08090d29f6491ce2ae4ea7cd0e7fb10167a6eb7b
ep_bytes: 53565755488d350a69f3ff488dbedbef
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Shelma.brwz also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.38235034
FireEyeGeneric.mg.47d77980ad9afbeb
ALYacTrojan.GenericKD.38235034
CylanceUnsafe
K7AntiVirusTrojan ( 0058280b1 )
AlibabaTrojanDropper:Win32/Shelma.fccaccf6
K7GWTrojan ( 0058280b1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of WinGo/TrojanDropper.Agent.J
APEXMalicious
KasperskyTrojan.Win32.Shelma.brwz
BitDefenderTrojan.GenericKD.38235034
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.38235034
TrendMicroBackdoor.Win64.SWRORT.YXBLJZ
McAfee-GW-EditionBehavesLike.Win64.Trickbot.cc
EmsisoftTrojan.GenericKD.38235034 (B)
GDataTrojan.GenericKD.38235034
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1202008
Antiy-AVLTrojan/Generic.ASBOL.C5E3
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D2476B9A
ViRobotTrojan.Win32.Z.Shelma.826880
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
McAfeeRDN/Generic Dropper
MAXmalware (ai score=85)
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallBackdoor.Win64.SWRORT.YXBLJZ
IkarusTrojan-Dropper.WinGo.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/Rozena.CL!tr
AVGWin64:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.Shelma.brwz?

Trojan.Win32.Shelma.brwz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment