Trojan

Should I remove “Trojan-Downloader.MSIL.Deyma”?

Malware Removal

The Trojan-Downloader.MSIL.Deyma is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.MSIL.Deyma virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.MSIL.Deyma?


File Info:

crc32: 9C1011E8
md5: 9f5b3233a09cbc2a6be5592c04818107
name: 9F5B3233A09CBC2A6BE5592C04818107.mlw
sha1: 11af7762dc3191aff048c69efeee179bf08eca01
sha256: 3abf994676885a4d49e44a5c99b311177f413aafdf2ec782735e505c2799e644
sha512: 0e71d5d65db669f25a899455e3c088ca56f32ed84dc3f971ee5a2a6a9cff25602060f28218d15bf000dc9bd6dc8009c5bf126712a4886bbebb35874e9575ee10
ssdeep: 3072:15g2nbLUpdrMyim7jg1HvhWxxVE1fshXA:1Ss1m7jgdhnf5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WsatConfig.exe
FileVersion: 4.8.3761.0 built by: NET48REL1
CompanyName: Microsoft Corporation
PrivateBuild: DDBLD438
Comments: Flavor=Retail
ProductName: Microsoftxae .NET Framework
ProductVersion: 4.8.3761.0
FileDescription: MB Version update tool
OriginalFilename: WsatConfig.exe
Translation: 0x0409 0x04b0

Trojan-Downloader.MSIL.Deyma also known as:

Elasticmalicious (high confidence)
FireEyeTrojan.GenericKD.36282093
Qihoo-360Win32/TrojanDownloader.Generic.HgIASOQA
McAfeeGenericRXNL-FC!9F5B3233A09C
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 00576f421 )
AlibabaTrojanDownloader:MSIL/Deyma.875905f3
K7GWTrojan-Downloader ( 00576f421 )
CyrenW32/Trojan.MHLD-4918
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 90)
KasperskyHEUR:Trojan-Downloader.MSIL.Deyma.gen
BitDefenderTrojan.GenericKD.36282093
Paloaltogeneric.ml
AegisLabTrojan.MSIL.Deyma.a!c
MicroWorld-eScanTrojan.GenericKD.36282093
TencentMsil.Trojan-downloader.Agent.Hwcx
Ad-AwareTrojan.GenericKD.36282093
EmsisoftTrojan.GenericKD.36282093 (B)
F-SecureTrojan.TR/Dldr.Agent.uvcmg
DrWebTrojan.DownLoaderNET.116
TrendMicroTROJ_GEN.R002C0PB121
McAfee-GW-EditionGenericRXNL-FC!9F5B3233A09C
SophosMal/Generic-S
GDataWin32.Trojan.Agent.CHVQKX
AviraTR/Dldr.Agent.uvcmg
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2299EED
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Deyma.gen
MicrosoftExploit:O97M/CVE-2017-11882.BI!MTB
BitDefenderThetaGen:NN.ZemsilF.34804.gm0@a8s0uFli
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HHL
TrendMicro-HouseCallTROJ_GEN.R002C0PB121
IkarusTrojan-Downloader.MSIL.Agent
FortinetMSIL/Agent.HHI!tr
AVGWin32:Trojan-gen
PandaTrj/RnkBend.A

How to remove Trojan-Downloader.MSIL.Deyma?

Trojan-Downloader.MSIL.Deyma removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment