Trojan

About “Trojan.Win32.Shelma.trw” infection

Malware Removal

The Trojan.Win32.Shelma.trw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Shelma.trw virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Shelma.trw?


File Info:

crc32: B4F61D1C
md5: 89a0060668c89da814768a11e1a36e10
name: harmless.exe
sha1: 4057d170dfbf796beed8d5078332419f1b494edd
sha256: e79c18edd1e560a5624f03b940dd0688e18543b11e6983bf76e035ed00b8345d
sha512: 60377d3159994ec7ae28364102e075443152a6c61b01e9cbed11af1e83913dbe178d7f57021b7e42e2cac06204c6416c296da8fba567ec6d9e6a91cdb39780ef
ssdeep: 1536:cVIn7vLAsrHAslLS8Ti1nQyd9O3jKVfOGHoHow9d9Aq8qiv:cU/9rAstGGGFOqw9d9Aq8q
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Shelma.trw also known as:

MicroWorld-eScanTrojan.GenericKD.12470743
nProtectTrojan/W32.Agent.76800.ADQ
McAfeeRDN/Generic.com
VIPRETrojan.Win32.Generic!BT
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0DJA17
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9825
F-ProtW32/Betload.B.gen!Eldorado
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002C0DJA17
Paloaltogeneric.ml
GDataTrojan.GenericKD.12470743
KasperskyTrojan.Win32.Shelma.trw
BitDefenderTrojan.GenericKD.12470743
AegisLabTroj.W32.SchoolGirl.tnx1
Ad-AwareTrojan.GenericKD.12470743
SophosMal/Generic-S
F-SecureTrojan.GenericKD.12470743
ZillyaTrojan.Shelma.Win32.1026
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.lh
EmsisoftTrojan.GenericKD.12470743 (B)
CyrenW32/Betload.B.gen!Eldorado
JiangminTrojan.Generic.arpbl
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.DBE49D7
ZoneAlarmTrojan.Win32.Shelma.trw
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.Shelma.C2187988
ALYacTrojan.GenericKD.12470743
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/CI.A
TencentWin32.Trojan.Shelma.Ecua
IkarusTrojan.Win32.Shelma
FortinetW32/Shelma.TRW!tr
AVGWin32:Malware-gen
Cybereasonmalicious.1b8fb7
AvastWin32:Malware-gen
Qihoo-360Win32/Backdoor.d55

How to remove Trojan.Win32.Shelma.trw?

Trojan.Win32.Shelma.trw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment