Trojan

Trojan-Downloader.Win32.Deyma.cin removal tips

Malware Removal

The Trojan-Downloader.Win32.Deyma.cin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Deyma.cin virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates a hidden or system file
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

postbackstat.biz
56.jpgamehome.com

How to determine Trojan-Downloader.Win32.Deyma.cin?


File Info:

crc32: 4449601B
md5: 2ec86535933f0b0a03d936f0718bbc5c
name: 2EC86535933F0B0A03D936F0718BBC5C.mlw
sha1: 17eb6f182eef7ae3cc5d1afae97585a827ec5a05
sha256: 5c4456803b09ab29c528d0ceeabed717af4b40fc8154a0f04eeea453bdf553ed
sha512: 21628f8849545430026f13102b4668f59cba58da7541d61cd9b955cb3932550d8be4c34d4ab2a53a7391e074304d92d65a890ea6179c791e1bed854b671197f5
ssdeep: 393216:JQQbfhPKkPKAma9Mrb7L/8A7OqHwCLjqfKlZG9KKQ0iB6V:JQAft/KAn9uUAfPLjqfK2iU
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Deyma.cin also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.45528
MicroWorld-eScanDropped:Trojan.GenericKDZ.79325
ALYacDropped:Trojan.GenericKDZ.79325
Cybereasonmalicious.82eef7
CyrenW32/MSIL_Troj.CY.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Pswtool-9857487-0
KasperskyTrojan-Downloader.Win32.Deyma.cin
BitDefenderDropped:Trojan.GenericKDZ.79325
TrendMicroTROJ_GEN.R002C0DKG21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.2ec86535933f0b0a
AviraHEUR/AGEN.1144141
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.34D1609
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataDropped:Trojan.GenericKDZ.79325
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R002H07KI21
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:cmRtazoxBX3ymh/hVS9UxWw4NQsJ)
IkarusWin32.Outbreak
FortinetMalicious_Behavior.SB
AVGWin32:PWSX-gen [Trj]

How to remove Trojan-Downloader.Win32.Deyma.cin?

Trojan-Downloader.Win32.Deyma.cin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment