Trojan

How to remove “Trojan.Win64.Shelma.rcf”?

Malware Removal

The Trojan.Win64.Shelma.rcf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Shelma.rcf virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Win64.Shelma.rcf?


File Info:

name: B00209182015ECBE3A60.mlw
path: /opt/CAPEv2/storage/binaries/57831237f1d1b20fb48ebc55fea51d3f4214d1a2241299762a8aec4126fa34ba
crc32: D1DF37EF
md5: b00209182015ecbe3a60b6b609ad2e85
sha1: e2d1904b2b3fb0cfdddf9396f52a469bc88c25a8
sha256: 57831237f1d1b20fb48ebc55fea51d3f4214d1a2241299762a8aec4126fa34ba
sha512: d3654f268fd4fa1f2771858ce28f0c170c1797b6560b52937a82ec33da9a162821e321988062e85f78c208e61e2079db38655927bc905727b48c7291c4cc28ee
ssdeep: 6144:qdk//SoFsj9pj1mWHvbXSHDR0P8+DAcq6aoIbrJ6hFlmVJMEAukm:d/KoFk3j1hDXSHDI3HJaxbruFlmVvM
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T10784236942A3CE9CC2C78F724B2BE89A2CB034477A665F4E091533E19D5FB904617F4E
sha3_384: d46d1f714ac43294e96ab143011481609bcd49986dca3a266907b686af906fb3dbe7462fa7e1f8d9ce0a6d64d57ab6e1
ep_bytes: 53565755488d353afcf9ff488dbedb5f
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Feijiu medical Beijing Corporation
FileDescription: 飞救医疗科技(北京)有限公司
FileVersion: v1.3.6.0
InternalName: Bianque.exe
LegalCopyright: Copyright (c) 2021 Feijiu medical Beijing Corporation
ProductName: WebTransEncryption
ProductVersion: v1.0.0.0
Translation: 0x0409 0x04b0

Trojan.Win64.Shelma.rcf also known as:

CylanceUnsafe
K7AntiVirusTrojan ( 0056eeaa1 )
AlibabaTrojan:Win64/Shelma.dd54705e
K7GWTrojan ( 0056eeaa1 )
Cybereasonmalicious.b2b3fb
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Rozena.FJ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win64.Shelma.rcf
AvastWin64:Trojan-gen
TrendMicroBackdoor.Win64.SWRORT.YXBLIZ
McAfee-GW-EditionBehavesLike.Win64.Generic.fc
SophosMal/Generic-S
GDataMSIL.Backdoor.Rozena.C0O59B
AviraHEUR/AGEN.1138546
Antiy-AVLGrayWare/Win32.Kryptik.eahk
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!B00209182015
TrendMicro-HouseCallBackdoor.Win64.SWRORT.YXBLIZ
IkarusBackdoor.SunShuttle
FortinetW64/Rozena.FJ!tr
AVGWin64:Trojan-gen

How to remove Trojan.Win64.Shelma.rcf?

Trojan.Win64.Shelma.rcf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment