Trojan

Should I remove “Trojan-Downloader.Win32.Deyma.bjl”?

Malware Removal

The Trojan-Downloader.Win32.Deyma.bjl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Deyma.bjl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Trojan-Downloader.Win32.Deyma.bjl?


File Info:

crc32: CFC03BD4
md5: a187fc68133419d137a141c2913b4f86
name: 510o9i8u.exe
sha1: d206df36b0f1e845e577c9685bbc86e60cc1d7a8
sha256: a6f4bc090d315cb57b303a52d6f9f0d02ddd423525cb0e3224f1c394f44ce2e9
sha512: 289c205eb6a82d0ca5d8ca516770ea1f38482cf6eb9cca4d0f33956a08582a9e47c99cdafd1bad288ecec94cc4dabfc881424da1c1c1143e17998549f7c2faed
ssdeep: 12288:W6qx+GgJOpEheBWpJ0NjYZZRKFdCFqPryQ32E9i/4B:8QlmWpJGYZZ4FsFEpn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003
InternalName: IrdaMobile
FileVersion: 1, 0, 0, 1
ProductName: IrdaMobile Application
ProductVersion: 1, 0, 0, 1
FileDescription: IrdaMobile MFC Application
OriginalFilename: IrdaMobile.EXE
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Deyma.bjl also known as:

MicroWorld-eScanGen:Variant.Zusy.309437
FireEyeGeneric.mg.a187fc68133419d1
McAfeeGenericRXLK-NT!A187FC681334
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056aa1a1 )
BitDefenderGen:Variant.Zusy.309437
K7GWTrojan ( 0056aa1a1 )
TrendMicroTROJ_GEN.R057C0DGI20
F-ProtW32/Kryptik.BQI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Zusy.309437
KasperskyTrojan-Downloader.Win32.Deyma.bjl
AlibabaTrojanDownloader:Win32/Deyma.3bcb0724
NANO-AntivirusTrojan.Win32.Dwn.hnydzy
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!1.C80B (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Ryuk.eqtqz
DrWebTrojan.DownLoader33.64957
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.309437 (B)
IkarusTrojan.SuspectCRC
CyrenW32/Kryptik.BQI.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/AD.Ryuk.eqtqz
MAXmalware (ai score=84)
Antiy-AVLTrojan[Downloader]/Win32.Deyma
ArcabitTrojan.Zusy.D4B8BD
ZoneAlarmTrojan-Downloader.Win32.Deyma.bjl
MicrosoftTrojan:Win32/Emotet.DGB!MTB
AhnLab-V3Malware/Win32.Generic.C4160581
VBA32BScope.Backdoor.Emotet
ALYacGen:Variant.Zusy.309437
Ad-AwareGen:Variant.Zusy.309437
MalwarebytesTrojan.Injector
PandaTrj/Genetic.gen
ESET-NOD32a variant of Generik.JKFXMQ
TrendMicro-HouseCallTROJ_GEN.R057C0DGI20
TencentMalware.Win32.Gencirc.10cde088
FortinetW32/Kryptik.HDKU!tr
BitDefenderThetaGen:NN.ZexaE.34136.Sq1@aKgD!2xi
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Downloader.83f

How to remove Trojan-Downloader.Win32.Deyma.bjl?

Trojan-Downloader.Win32.Deyma.bjl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment