Trojan

Trojan-Downloader.Win32.Deyma.cdj removal tips

Malware Removal

The Trojan-Downloader.Win32.Deyma.cdj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Deyma.cdj virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Deyma.cdj?


File Info:

crc32: C3740A96
md5: a9d35b3546a908c804d177020daefcb0
name: A9D35B3546A908C804D177020DAEFCB0.mlw
sha1: 1ba9d78409d3188653fcb003d618b97a276577fa
sha256: 45193fa14de60908b958e3f268ef46457acbbe4d7b63784a8dc177a510528827
sha512: fb03bd4f20493bfd41e013102162e3ca4b3e084f2be6caf8311c0e772d55ebb8b753f5bcc2397cc0f0b9298ac51da27b96232c858c9bbfcedf00b23db04cd337
ssdeep: 196608:XPGZKb8EmARpfMWw93Axfy46VqPFUXd8hSXJTkWOg0rmt+kK1:+o7pa9wVaqcd8hSZkWOgOmHq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2018 Indigo Rose Corporation
InternalName: suf_launch
FileVersion: 9.5.2.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory
ProductName: Setup Factory Runtime
ProductVersion: 9.5.2.0
FileDescription: Setup Application
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Deyma.cdj also known as:

LionicTrojan.Win32.Deyma.a!c
DrWebTrojan.DownLoader41.9312
MicroWorld-eScanTrojan.GenericKD.37397275
ALYacTrojan.GenericKD.37397275
ZillyaTrojan.AveMaria.Win32.17
SangforTrojan.Win32.Deyma.cdj
AlibabaTrojanDownloader:Win32/Deyma.60588dca
CyrenW32/Kryptik.DOL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACYJ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Downloader.Win32.Deyma.cdj
BitDefenderTrojan.GenericKD.37397275
Ad-AwareTrojan.GenericKD.37397275
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
FireEyeGeneric.mg.a9d35b3546a908c8
EmsisoftTrojan.GenericKD.37397275 (B)
KingsoftWin32.TrojDownloader.Deyma.c.(kcloud)
GDataTrojan.GenericKD.37397275
McAfeeArtemis!A9D35B3546A9
MAXmalware (ai score=81)
VBA32TrojanPSW.Convagent
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R023H0CHD21
IkarusTrojan.Win32.Agent
FortinetW32/Deyma.CDJ!tr.dldr
AVGWin32:Trojan-gen
Qihoo-360Win32/TrojanDownloader.Generic.HgIASaMA

How to remove Trojan-Downloader.Win32.Deyma.cdj?

Trojan-Downloader.Win32.Deyma.cdj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment