Trojan

Trojan.Win32.Shlem information

Malware Removal

The Trojan.Win32.Shlem is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Shlem virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the CobaltStrikeBeacon malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Win32.Shlem?


File Info:

name: 18CAD05D7C898A386C3E.mlw
path: /opt/CAPEv2/storage/binaries/26d6879e315e6ea57792864e214206ef0a800ac3ab919013f5e5f35715bc8a37
crc32: 122EAFE0
md5: 18cad05d7c898a386c3e0f84e1be5a16
sha1: 679c740c4d413201bbbb20f5c554ce470b3ea53a
sha256: 26d6879e315e6ea57792864e214206ef0a800ac3ab919013f5e5f35715bc8a37
sha512: b975d16fecbfc0e4a6cf33ffdb18874987fdb1501cc37699a8bd0cb5c97c0d2896243afde222221d9c7b54cc79d11552f4b24c06e7cf4225271bd564f191cb73
ssdeep: 49152:kp4k5rCuAT0ajhrABNl8tMvFNGggXXpDYALLRENU9Qd+buk5HxjC5dJdVqQAqemh:pk9CVTPjhcB/WXWU9w6Z5HEpb56HW
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17F965ACB16AD8731E29D0EB55C6C49900768EC02BB2DAECB3C45787B85772C8757A3D2
sha3_384: cd1e621ae45f81ff4f6fdafff703377d95c1b2c64d71cf976af418e831be71dac18dc945c71539ae7722f3aec704eb74
ep_bytes: e9e1f13800e91af23800e968fb3800e9
timestamp: 2022-09-26 16:29:50

Version Info:

CompanyName: Avira Operations GmbH & Co. KG
FileDescription: Avira Security
FileVersion: 1.0.33.2
InternalName: avira.exe
LegalCopyright: Copyright © 2022 Avira Operations GmbH & Co. KG and its Licensors
OriginalFilename: avira.exe
ProductName: Avira Security
ProductVersion: 1.0.33.2
Translation: 0x0000 0x04b0

Trojan.Win32.Shlem also known as:

McAfeeArtemis!18CAD05D7C89
SangforTrojan.Win32.Shlem.gen
AlibabaTrojan:Win32/CobaltStrike.550b7082
KasperskyHEUR:Trojan.Win32.Shlem.gen
RisingTrojan.Generic!8.C3 (TFE:5:XZC5GUNJ9DB)
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.18cad05d7c898a38
AviraTR/AD.CobaltStrike.pskpt
Antiy-AVLTrojan/Generic.ASMalwS.826C
ZoneAlarmHEUR:Trojan.Win32.Shlem.gen
CynetMalicious (score: 99)
VBA32BScope.Trojan.Wacatac
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H07J422
TencentWin32.Trojan.FalseSign.Itgl
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan.Win32.Shlem?

Trojan.Win32.Shlem removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment