Malware

Win32/DelShad.B removal instruction

Malware Removal

The Win32/DelShad.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DelShad.B virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Modifies Image File Execution Options, indicative of process injection or persistence
  • Creates known PcClient mutex and/or file changes.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/DelShad.B?


File Info:

name: A24635BF5F786591B541.mlw
path: /opt/CAPEv2/storage/binaries/870d99f50bd6cb6f5f02bbde1545196b699230e7093a4efcd9020f477a1c6dcd
crc32: 9F8FDF35
md5: a24635bf5f786591b5410e7250117d2e
sha1: e398c44110bdf3ec5ff2af1de30b2ca2224140b4
sha256: 870d99f50bd6cb6f5f02bbde1545196b699230e7093a4efcd9020f477a1c6dcd
sha512: 8e7d2b5578bffef81dd4e1cbd2bd9bbead223dd7f1bb468313d21659e2d28ee7f4bff837aec80a9d99c4c56564cfa62ea651684d09fdc172e534e02036abe761
ssdeep: 49152:Al4IZR+LVdC4Pt3yBM6ly01WcJMoSwfnurCRFOVcovutSYMk5bMyA:hIZRkVdj6n+IGrCRFO7vutSYZuyA
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T187E5233EB66C48B4CA2AC079CF95AA4AD7B2F504439083DB5154CBB34E27FA4AC2D355
sha3_384: 78abf42ab866f81e3e3bb466da712dbcd2abf8b6834c1af9e891d0ac2b81c0352fe3050f50eb3e46e2b895f6a1e8ee42
ep_bytes: 4883ec28e8f30100004883c428e9eafc
timestamp: 2012-12-31 00:39:34

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x64)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x64.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Win32/DelShad.B also known as:

AVGWin64:Trojan-gen
MicroWorld-eScanTrojan.GenericKD.46108406
FireEyeTrojan.GenericKD.46108406
ALYacTrojan.GenericKD.46108406
MalwarebytesTrojan.Agent.HDC.Generic
VIPRETrojan.GenericKD.46108406
SangforRansom.Win32.DelShad.mt
AlibabaTrojan:Win32/DelShad.0cc3c8fc
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/DelShad.B
KasperskyTrojan.Win32.DelShad.gdn
BitDefenderTrojan.GenericKD.46108406
AvastWin64:Trojan-gen
EmsisoftTrojan.GenericKD.46108406 (B)
McAfee-GW-EditionBehavesLike.Win64.Generic.wc
SophosMal/Generic-S
GDataTrojan.GenericKD.46108406
JiangminRiskTool.Agent.aze
MAXmalware (ai score=80)
XcitiumMalware@#20no0ivxp1nuj
ArcabitTrojan.Generic.D2BF8EF6
ZoneAlarmTrojan.Win32.DelShad.gdn
MicrosoftRansom:Win32/DelShad
GoogleDetected
McAfeeArtemis!A24635BF5F78
VBA32Trojan.DelShad
Cylanceunsafe
TencentWin32.Trojan.Delshad.Lajl
YandexTrojan.DelShad!ETvC3U6Ffic
IkarusTrojan.Win32.Delshad
MaxSecureTrojan.Malware.74134469.susgen
FortinetBAT/DelShad.B!tr.ransom
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/DelShad.B?

Win32/DelShad.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment