Trojan

Should I remove “Trojan.Win32.Shelma.cgfm”?

Malware Removal

The Trojan.Win32.Shelma.cgfm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Shelma.cgfm virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Shelma.cgfm?


File Info:

name: A742B6E591DD8A28C1C6.mlw
path: /opt/CAPEv2/storage/binaries/bb28395dbeb86e63b4bf95c7ba1b286daed3177cbb667ddb28867f4103f196ba
crc32: 78648280
md5: a742b6e591dd8a28c1c6792d0cd58d44
sha1: f33909f01e83dce62a4e106a5cfe7060bf930aad
sha256: bb28395dbeb86e63b4bf95c7ba1b286daed3177cbb667ddb28867f4103f196ba
sha512: 50ab8e6e5de48d35a291e828e81bcec21d33436f0a939a7a4f06efbd7dc6f3f9baf5cdf55c647645fcb28d0ca6ec581f3e8ddac12dafa9345d02b4eac236de5e
ssdeep: 1536:x3A+wAwKgNEp+fTnlOR/+xtuHnK6p2RogjUbT:xw8wKgN9fTno5qtuvKogsT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17D537D8375D1D1F5F50166B018F6EBBA6F3B922A16230597FB0CCDA61B322B0E52634D
sha3_384: d240b244d245cc14092eeb399556e906807a1b157a945ab11fed9bc3429318c315173b541d3a43f85f9cc57f7b56c767
ep_bytes: 558bec6aff6800b04000687876400064
timestamp: 1998-01-03 19:17:13

Version Info:

0: [No Data]

Trojan.Win32.Shelma.cgfm also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.NetCat.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.NetTool.A
FireEyeGeneric.mg.a742b6e591dd8a28
CAT-QuickHealTrojan.NetcatPMF.S2872974
McAfeeArtemis!A742B6E591DD
MalwarebytesRozena.Trojan.Shell.DDS
ZillyaAdware.MultiPlug.Win32.498770
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005970a11 )
AlibabaMalware:Win32/km_24e64b82.None
K7GWTrojan ( 005970a11 )
Cybereasonmalicious.591dd8
BitDefenderThetaGen:NN.ZexaF.36662.dqW@aeq482j
VirITBackdoor.Win32.Ncx.B
CyrenW32/Ncx.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RemoteAdmin.NetCat.AB potentially unsafe
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Shelma.cgfm
BitDefenderApplication.NetTool.A
NANO-AntivirusTrojan.Win32.Ncx.eplb
AvastWin32:PUP-gen [PUP]
TencentMalware.Win32.Gencirc.13ed0332
EmsisoftApplication.NetTool.A (B)
BaiduWin32.Backdoor.NCX.b
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTool.Netcat
VIPREApplication.NetTool.A
TrendMicroBackdoor.Win32.SWRORT.YXDHYZ
McAfee-GW-EditionBehavesLike.Win32.Infected.km
SophosNetCat (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Riskware.NetCat.C
JiangminHacktool.Nc
WebrootW32.Trojan.Orsam
AviraBDS/Backdoor.Gen
Antiy-AVLRiskWare[RemoteAdmin]/Win32.NetCat.alj
XcitiumTrojWare.Win32.TrojanDownloader.Agent.~DDG@9ro8v
ArcabitApplication.NetTool.A
ZoneAlarmTrojan.Win32.Shelma.cgfm
MicrosoftTrojan:Win32/Swrort.A
GoogleDetected
AhnLab-V3Trojan/Win32.HDC.C63607
ALYacApplication.NetTool.A
MAXmalware (ai score=73)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.Win32.SWRORT.YXDHYZ
RisingBackdoor.Ncx.b (CLASSIC)
IkarusTrojan.Win32.Swrort
MaxSecureTrojan.Malware.216127579.susgen
FortinetRiskware/NetCat
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Shelma.cgfm?

Trojan.Win32.Shelma.cgfm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment