Malware

Win32/WinShell.AA removal instruction

Malware Removal

The Win32/WinShell.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/WinShell.AA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/WinShell.AA?


File Info:

name: 6E819A370350D424FA57.mlw
path: /opt/CAPEv2/storage/binaries/2e7a0053d54870bbfda7c922fc630362a035a081c219b7b49572a3a5175ba137
crc32: C2F94122
md5: 6e819a370350d424fa576c0131f7d180
sha1: 079d212752a720d66ed66078aa025d34546f750d
sha256: 2e7a0053d54870bbfda7c922fc630362a035a081c219b7b49572a3a5175ba137
sha512: 65bd1759ee38be640552a844abbf4e9abef4e0292b5118c404f9cedf1e51a680f7326625e9432185fd4b3ef6c0bb7aa98cc6c59e02bdb3387b6fbd8b36723d94
ssdeep: 24576:xKrPoVXEyn1+04+g8IdlTZi+NHv7mOel7QDBolDD8O9MC+x:GP0Z1N3lCi+NH650BolDD19MCu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C54533A3741B482BD1B1E436520EBAD8FDF7F50B8D6839665E0BDC504531AE1E0C3A9B
sha3_384: 3ba8e18221e7e22e66b00f855225ef5f0fb8d5b06a46ec440ad18ffddb46ed74fdbf5fcfe0bac83b4b0e9ccad3d79800
ep_bytes: 60be00504e008dbe00c0f1ff5783cdff
timestamp: 2021-03-17 23:46:53

Version Info:

CompanyName: 厦门智业软件公司
FileDescription: Charge
FileVersion: 8.0.2.9506
InternalName: PB 8
LegalCopyright: Copyright (c) 1997 - 2008 ZHIY Corporation
ProductName: 收费工作站
ProductVersion: Version 4.1
Translation: 0x0409 0x1252

Win32/WinShell.AA also known as:

MicroWorld-eScanGen:Trojan.Heur.D.cGW@d0Ck0Ypb
FireEyeGeneric.mg.6e819a370350d424
ALYacGen:Trojan.Heur.GC.cm0@ujzYTbab1
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 004e7cd61 )
Cybereasonmalicious.70350d
BitDefenderThetaAI:Packer.394AFB101D
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/WinShell.AA
TrendMicro-HouseCallTROJ_GEN.R011C0PGD22
ClamAVWin.Packed.Agent-9885051-0
KasperskyTrojan.Win32.Bingoml.fhgn
BitDefenderGen:Trojan.Heur.D.cGW@d0Ck0Ypb
AvastFileRepMalware [Trj]
Ad-AwareGen:Trojan.Heur.D.cGW@d0Ck0Ypb
SophosMal/Generic-S
DrWebBackDoor.WinShell.74
VIPREGen:Trojan.Heur.D.cGW@d0Ck0Ypb
TrendMicroTROJ_GEN.R011C0PGD22
McAfee-GW-EditionBehavesLike.Win32.Ipamor.tc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.D.cGW@d0Ck0Ypb (B)
APEXMalicious
GDataGen:Trojan.Heur.GC.cm0@ujzYTbab1
AviraTR/Crypt.CFI.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!5C56337E9B82
MAXmalware (ai score=86)
VBA32BScope.Backdoor.VB
MalwarebytesMalware.Heuristic.1003
RisingTrojan.WinShell!8.2CB6 (CLOUD)
IkarusTrojan.Win32.WinShell
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/WinShell.AA!tr
AVGFileRepMalware [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/WinShell.AA?

Win32/WinShell.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment