Trojan

Trojan-Downloader.Win32.Deyma.cbp (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Deyma.cbp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Deyma.cbp virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Trojan-Downloader.Win32.Deyma.cbp?


File Info:

crc32: AD327A89
md5: 9872c5836f6267c8a7a0355af11fd10f
name: 9872C5836F6267C8A7A0355AF11FD10F.mlw
sha1: 0eb9b07c1f75fbf056f1502bd3edbdb448164734
sha256: 4dc35908a0885511857ea610a559c4aebe99231ba8493e95885512f0f98293ed
sha512: 7ef19d46454f1ece002ed7d9a42532c56ff4ed9cbaece6ff9b088d3801dd6616339f9dcb488adb6a3cbbca520a5fcfd6547d70865407d3cf0a8bb22d43aa568a
ssdeep: 98304:87Pb17RLe6OmPZFvKDAOKPfITyQERKlMNSrZ:81FLe6BFvkKPcQLNSF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: labsofte polish 2021 @gov.pl
Assembly Version: 31.8.3.7
InternalName: CodeGroupStack.exe
FileVersion: 31.8.3.7
CompanyName: labsofte polish
LegalTrademarks: Installer for Europe 2021 LLC
Comments: Installer for Europe
ProductName: gnu all langwidge
ProductVersion: 31.8.3.7
FileDescription: License Blockchain Editor
OriginalFilename: CodeGroupStack.exe

Trojan-Downloader.Win32.Deyma.cbp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ALYacTrojan.GenericKD.37150498
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Deyma.89f34d1e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c1f75f
CyrenW32/Trojan.CONV-7674
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Deyma.cbp
BitDefenderTrojan.GenericKD.37150498
MicroWorld-eScanTrojan.GenericKD.37150498
Ad-AwareTrojan.GenericKD.37150498
SophosGeneric PUA AO (PUA)
DrWebTrojan.Siggen14.6743
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.9872c5836f6267c8
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Deyma.wd
AviraTR/Dldr.Deyma.twbaa
ArcabitTrojan.Generic.D236DF22
AegisLabTrojan.Win32.Deyma.a!c
ZoneAlarmTrojan-Downloader.Win32.Deyma.cbp
AhnLab-V3Trojan/Win.Generic.C4535752
Acronissuspicious
McAfeeArtemis!9872C5836F62
MAXmalware (ai score=86)
VBA32TrojanDownloader.Deyma
MalwarebytesTrojan.Amadey
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R049C0WFS21
RisingTrojan.Generic@ML.87 (RDMK:bQduwh/HjI2BSiSdVehUpw)
FortinetRiskware/VMProtectPacked
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Deyma.cbp?

Trojan-Downloader.Win32.Deyma.cbp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment