Shylock, a non-Zeus-based information-stealing trojan, was discovered by Trusteer in 2011. It is named after the ruthless money lender in Shakespeare’s The Merchant of Venice. It also deletes its installation files, runs solely in memory, and begins the process again once the infected machine reboots. It uses a new trick to detect whether it’s running in a virtual machine that is being analyzed by malware researchers. However, it is unclear how long such a trick will help it evade detection because evasion tactics aren’t actually that effective.
Source: https://thehackernews.com/2012/12/shylock-malware-undetectable-virus.html

