Trojan

How to remove “Trojan.Caynamer”?

Malware Removal

The Trojan.Caynamer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Caynamer virus can do?

  • Executable code extraction
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
freekzvideo.cloud

How to determine Trojan.Caynamer?


File Info:

crc32: 6D4C2213
md5: 66cf75712019f76c23d6125bf8980486
name: id2.exe
sha1: b0b61ea30f4987abe977b96a2898a5a286a2a6b6
sha256: ee218d62febd1a7e31ca49f1796e279724cfcc27be6387a18fe86712a3ae2513
sha512: 504b20ae9c827d9ed9bfd5903aaad227d6243ec2b2a8acc6736010e146c94d5b324e11f22786804964ddd75ef4108f87a68fa97459092390880c0de87d453117
ssdeep: 12288:9gJEhJtB8vEhmsMo2TQBoT+foa5FelX9txambQE38FK5VlcBG5Ga0sCmse3n+KH:9gJHEhC13T+Aa7yPIvc1OEyAFVF1x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2020
InternalName: 20200801
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: 20200801 x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: 20200801 Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: 20200801.EXE
Translation: 0x0804 0x04b0

Trojan.Caynamer also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.29066
MicroWorld-eScanGen:Variant.Midie.74193
FireEyeGen:Variant.Midie.74193
CAT-QuickHealTrojan.IGENERIC
Qihoo-360Win32/Trojan.Dropper.825
ALYacGen:Variant.Midie.74193
CylanceUnsafe
ZillyaTrojan.Socelars.Win32.615
SangforMalware
K7AntiVirusTrojan ( 00569c7c1 )
AlibabaTrojanSpy:Win32/Socelars.eb8c63ee
K7GWTrojan ( 00569c7c1 )
CyrenW32/Trojan.VRXX-8727
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderGen:Variant.Midie.74193
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.11aaf297
Ad-AwareGen:Variant.Midie.74193
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1136969
BaiduWin32.Trojan.Farfli.bc
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.EMOTET.USXVPHE20
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
JiangminTrojanDropper.Generic.dus
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1136969
Antiy-AVLTrojan[Spy]/Win32.Socelars
MicrosoftTrojan:Win32/Ymacco.AAEE
ArcabitTrojan.Midie.D121D1
AegisLabTrojan.Win32.Generic.b!c
ZoneAlarmHEUR:Trojan-Dropper.Win32.Generic
GDataGen:Variant.Midie.74193
McAfeeGenericRXLP-SB!66CF75712019
MAXmalware (ai score=88)
VBA32Trojan.Caynamer
MalwarebytesSpyware.Socelars
ESET-NOD32Win32/Spy.Socelars.AD
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.USXVPHE20
RisingDropper.Generic!8.35E (TFE:dGZlOgVW3NV9A7BmJA)
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.PVDK!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.1698455.susgen

How to remove Trojan.Caynamer?

Trojan.Caynamer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment