Spy Trojan

TrojanSpy:Win32/Shevonelo.STA malicious file

Malware Removal

The TrojanSpy:Win32/Shevonelo.STA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Shevonelo.STA virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanSpy:Win32/Shevonelo.STA?


File Info:

crc32: 364434BD
md5: 1ddd876da3731823324ffa302ddddcba
name: 1DDD876DA3731823324FFA302DDDDCBA.mlw
sha1: 2f6d73554c05dbda6cd738a2f38d5cdae2cdd4b7
sha256: 045a7318a9e2e550208c0c7e9fc805068df19fa73823ac3acaa049a46c4045ee
sha512: 88f453489949abdf85f733b746c7d1983ccd84d8c528840fdd749c207d97acb1ef3b87487e0f4eb3a9965450c51b3bf2230ad0dfff0b6c6b318b24b6c24911c5
ssdeep: 3072:AomnzVincQDKgclXgnQiQlo4SssssIkHYBTeQCbMrJ56kkOIgZtF48:AtZZXgnQiKo4+Ye+H6kEgbr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2020 philandro Software GmbH
FileVersion: 6.1.0.0
CompanyName: philandro Software GmbH
ProductName: AnyDesk
ProductVersion: 6.1
FileDescription: AnyDesk
Translation: 0x0409 0x04e4

TrojanSpy:Win32/Shevonelo.STA also known as:

Elasticmalicious (high confidence)
Qihoo-360Win32/Trojan.Generic.HyoDimEA
McAfeeArtemis!1DDD876DA373
MalwarebytesTrojan.Downloader
AegisLabTrojan.Win32.Injects.4!c
SangforTrojan.Win32.Ymacco.AA04
K7AntiVirusTrojan ( 0057868f1 )
BitDefenderTrojan.GenericKD.36417302
K7GWTrojan ( 0057868f1 )
ArcabitTrojan.Generic.D22BAF16
CyrenW32/Trojan.RYII-3306
SymantecTrojan.Gen.MBT
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.Win32.Injects.gen
AlibabaTrojan:Win32/GenCBL.9e36f771
NANO-AntivirusTrojan.Win32.GenCBL.imlfbp
MicroWorld-eScanTrojan.GenericKD.36417302
Ad-AwareTrojan.GenericKD.36417302
SophosMal/Generic-S
ComodoMalware@#27i9wvofw7s84
F-SecureHeuristic.HEUR/AGEN.1140714
DrWebTrojan.MulDrop16.11606
TrendMicroTROJ_FRS.VSNTC121
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36417302
EmsisoftMalCert.A (A)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1140714
MAXmalware (ai score=84)
GridinsoftTrojan.Win32.Downloader.sa
MicrosoftTrojanSpy:Win32/Shevonelo.STA
ViRobotTrojan.Win32.Z.Gencbl.279640
ZoneAlarmHEUR:Trojan.Win32.Injects.gen
GDataTrojan.GenericKD.36417302
AhnLab-V3Trojan/Win32.BuerLoader.C4347265
ALYacTrojan.GenericKD.36417302
CylanceUnsafe
ESET-NOD32a variant of Win32/GenCBL.AAK
TrendMicro-HouseCallTROJ_FRS.VSNTC121
RisingTrojan.Injector/NSIS!1.BFBB (CLASSIC)
IkarusTrojan.NSIS.Agent
FortinetW32/GenCBL.AAK!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanSpy:Win32/Shevonelo.STA?

TrojanSpy:Win32/Shevonelo.STA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment