Trojan

Should I remove “Trojan-Dropper.Win32.Demp.aszo”?

Malware Removal

The Trojan-Dropper.Win32.Demp.aszo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Demp.aszo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Dropper.Win32.Demp.aszo?


File Info:

name: 7E919B1124EF4A2ECE92.mlw
path: /opt/CAPEv2/storage/binaries/26dd04134329d016ca698899e3bc0ffb25d14af55049d95188759679acd667a9
crc32: F78CCDD1
md5: 7e919b1124ef4a2ece92c261858af05e
sha1: 6ff51b514835be96f8d2fd9cddaa2f6ea090d451
sha256: 26dd04134329d016ca698899e3bc0ffb25d14af55049d95188759679acd667a9
sha512: 8bff942e45476bccf831aa6c973921c7dfe1ca33502a448026e876a144653214700631b914f93c386e161bd01cabd881be49d6effc40987de67af3cdbf63dc3b
ssdeep: 24576:I5q4XR/5Pnp5ItYM/ABtAbghHXjRZqtSIU06jNnuK+raA+gVTPlc5/N8Cb:V4t9IWtZ3WtSHRuK+rbVGj8Cb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E635232E3C3487A0E815C7308A35A7710512BD44EE76889FF500B3EFAB756A2763B5B5
sha3_384: 6e0fa399e6e6eaa4b5efa6c374c15dca90779ce01128532f43fb17e199f8187868164b740aad4047cb10fbc0acee33fb
ep_bytes: 558bec83ec4456ff15a04040008bf08a
timestamp: 2011-04-26 16:15:03

Version Info:

CompanyName: LogMeIn, Inc.
FileDescription: LogMeIn Rescue
FileVersion: 6.3.377
InternalName: Rescue
LegalCopyright: Copyright © 2005-2011 LogMeIn, Inc. US patents pending.
OriginalFilename: LMIRescue.exe
ProductName: LogMeIn Rescue
ProductVersion: 6.3.377
Translation: 0x0409 0x04b0

Trojan-Dropper.Win32.Demp.aszo also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Demp.b!c
McAfeeArtemis!7E919B1124EF
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.14835b
KasperskyTrojan-Dropper.Win32.Demp.aszo
NANO-AntivirusTrojan.Win32.Demp.cwgcxh
RisingTrojan.Generic@AI.94 (RDML:A7yt8jNvGgFaUvf/5fYEdQ)
DrWebTrojan.Siggen3.38887
ZillyaDropper.Demp.Win32.3280
McAfee-GW-EditionArtemis
Trapminesuspicious.low.ml.score
JiangminTrojanDropper.Demp.agp
XcitiumTrojWare.Win32.TrojanDropper.Daws.AWVZ@7pjjd8
ZoneAlarmTrojan-Dropper.Win32.Demp.aszo
VBA32TrojanDownloader.Agent
Cylanceunsafe
TencentWin32.Trojan-Dropper.Demp.Itgl
YandexTrojan.Agent!YyySvqI1AJg
MaxSecureTrojan.Malware.12299776.susgen
FortinetW32/Demp.ASZO!tr
DeepInstinctMALICIOUS

How to remove Trojan-Dropper.Win32.Demp.aszo?

Trojan-Dropper.Win32.Demp.aszo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment