Trojan

Trojan:Win32/Dkshell.A removal tips

Malware Removal

The Trojan:Win32/Dkshell.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dkshell.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Dkshell.A?


File Info:

crc32: E207080A
md5: ab111ef42b3fddb5c95e98e0c3f305bb
name: AB111EF42B3FDDB5C95E98E0C3F305BB.mlw
sha1: d19971220de36ccb3b37e880fdd70a5df538d2b6
sha256: 4a59523bb7154adc7818a29c5171512c1f0f5261db913d0a064531dd171d19c9
sha512: d7f924fbc4a285e9a898339c584e8fa25d0e7cc61a8d0ce7f110698388f7fd60f5c8ce5c3bafefccf35a6d71d32b568cd7a09198a78ea70be08c7a52dfd7a1fb
ssdeep: 1536:pmSXGWCbGtffja/W8ygJjhR5c6BLOtPYq4:pmSWDbaUyg1hzc6Bqix
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Dkshell.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.DarkShell.m!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.17520
CynetMalicious (score: 100)
ALYacGen:Trojan.Generic.di0aaO2RSfeb
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.41410
SangforBackdoor.Win32.DarkShell.rs
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/DarkShell.a4e7adc6
Cybereasonmalicious.42b3fd
CyrenW32/Backdoor.UHRG-4929
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Agent.DKR
APEXMalicious
AvastFileRepMalware
KasperskyBackdoor.Win32.DarkShell.rs
BitDefenderGen:Trojan.Generic.di0aaO2RSfeb
NANO-AntivirusTrojan.Win32.Agent.iszz
MicroWorld-eScanGen:Trojan.Generic.di0aaO2RSfeb
TencentMalware.Win32.Gencirc.114c3b2c
Ad-AwareGen:Trojan.Generic.di0aaO2RSfeb
SophosMal/Behav-160
ComodoTrojWare.Win32.Agent.ORM@4rvz37
BitDefenderThetaAI:Packer.D91AAC4F1C
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_DEOL.A
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qc
FireEyeGeneric.mg.ab111ef42b3fddb5
EmsisoftGen:Trojan.Generic.di0aaO2RSfeb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agent.bbhq
WebrootTrojan:Win32/Dkshell.A
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.961C98
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Dkshell.A
ZoneAlarmBackdoor.Win32.DarkShell.rs
GDataGen:Trojan.Generic.di0aaO2RSfeb
AhnLab-V3Win-Trojan/Malpacked5.Gen
Acronissuspicious
McAfeeArtemis!AB111EF42B3F
MAXmalware (ai score=100)
VBA32Trojan.Wacatac
PandaGeneric Malware
TrendMicro-HouseCallTROJ_DEOL.A
RisingBackdoor.Darkshell!1.6684 (CLASSIC)
YandexBackdoor.Agent!a3XC48JmETY
IkarusBackdoor.Win32.Venik
MaxSecureVirus.Sality.AA
FortinetW32/DEOL.A!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan:Win32/Dkshell.A?

Trojan:Win32/Dkshell.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment