Trojan

Trojan.Win64.Shelma.crk removal guide

Malware Removal

The Trojan.Win64.Shelma.crk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Shelma.crk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Trojan.Win64.Shelma.crk?


File Info:

name: C862A57D039C37BCA449.mlw
path: /opt/CAPEv2/storage/binaries/697ece6d2e093077167f20efc90d1deade41db4c070fb13e04a914edfea2f786
crc32: B9E61A45
md5: c862a57d039c37bca449f3a2ae972311
sha1: df12ef059a98e164fc28bd51f27c2244f0c8df06
sha256: 697ece6d2e093077167f20efc90d1deade41db4c070fb13e04a914edfea2f786
sha512: 9779815911de936c23ae174f0ae1295eb5db36cb3cd7160d2d96f173bf28a5fde68814001521157cc115428f39890c6326e2e874181e82ede8e8e58392dd9510
ssdeep: 1536:iltgedH7On0ZQa4pBo2tZOoPMxIgvFQFeccbekkIyo+TfC:iltgedDZt4pBo+AoKiUccikLy7TfC
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T19F43F1BCEE69A5F2DA32253DC24B740B70741B1CE7FA560685F1B76B711A28B73812D0
sha3_384: 7c7f91b93dcaf6a2cb4d779e64a85bf3ba3d213bc09febbdb148c2804102b83a46dd5763be5e533ed81c93c5c863216d
ep_bytes: 57565351524150488d05de0a0000488b
timestamp: 2019-11-28 10:39:54

Version Info:

0: [No Data]

Trojan.Win64.Shelma.crk also known as:

LionicTrojan.Win64.Shelma.4!c
DrWebTrojan.DownLoader24.13459
MicroWorld-eScanTrojan.GenericKD.32773045
FireEyeGeneric.mg.c862a57d039c37bc
ALYacTrojan.GenericKD.32773045
CylanceUnsafe
ZillyaTrojan.Shelma.Win64.2001
SangforTrojan.Win32.PatchedWinSwrort.lkoev
AlibabaTrojan:Win64/Shelma.5b2847f7
Cybereasonmalicious.d039c3
SymantecTrojan.Gen.MBT
Paloaltogeneric.ml
KasperskyTrojan.Win64.Shelma.crk
BitDefenderTrojan.GenericKD.32773045
AvastWin64:Malware-gen
TencentWin64.Trojan.Shelma.Syri
Ad-AwareTrojan.GenericKD.32773045
SophosMal/Generic-S
ComodoMalware@#3ifomybp4l4nt
McAfee-GW-EditionBehavesLike.Win64.Trojan.qc
EmsisoftTrojan.GenericKD.32773045 (B)
IkarusTrojan.Patched
GDataTrojan.GenericKD.32773045
AviraTR/AD.PatchedWinSwrort.lkoev
ArcabitTrojan.Generic.D1F413B5
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeGeneric Trojan.jy
MAXmalware (ai score=82)
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetW64/Vabushky.A!tr
AVGWin64:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win64.Shelma.crk?

Trojan.Win64.Shelma.crk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment