Trojan

Trojan-Dropper.Win32.Dycler.zrj removal tips

Malware Removal

The Trojan-Dropper.Win32.Dycler.zrj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Dycler.zrj virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Dycler.zrj?


File Info:

name: 1D14C9DE0B4529C96BF3.mlw
path: /opt/CAPEv2/storage/binaries/684f0b51ee3bf720e053951b133d421af37d772299851454cf3fd70bff6ed93c
crc32: DC8D08FF
md5: 1d14c9de0b4529c96bf3e811f6ece668
sha1: 336ff1276dadbb83121bcbaf8993ecb0bb47a1d4
sha256: 684f0b51ee3bf720e053951b133d421af37d772299851454cf3fd70bff6ed93c
sha512: 7afbfa92aaf82f9277d000b903c3bedaddbd683b6e2cdd83d83e38fb1d486a4d24eba58b44e8cf5f1fb7e43b2ccaab53b97d01fa742451a2b893f02b6620e30f
ssdeep: 6144:JuUXgd5VrAWdCdZZ7ZwR93s9BMnWsOq3iAThRI21rWW3sY6vFAVEavIABr5Kr:JuUXgd5+2CdZZ23s9WWFAic6vrALl5Kr
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1C9849D6273D819E4F8739639C9369A11D5B23C565B71C3CF23A0664A2F33BD09C39B26
sha3_384: d8d1c3c41b7506050a6b211245863ca129bbf5c744c9c534b14f06db6e35cf69bcc247d1f5331729f02718b14d188540
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2017-07-22 05:15:32

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Web Start Launcher
FileVersion: 11.144.2.01
Full Version: 11.144.2.01
InternalName: Java(TM) Web Start Launcher
LegalCopyright: Copyright © 2017
OriginalFilename: javaws.exe
ProductName: Java(TM) Platform SE 8 U144
ProductVersion: 8.0.1440.1
Translation: 0x0000 0x04b0

Trojan-Dropper.Win32.Dycler.zrj also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Ulise.386969
FireEyeGen:Variant.Ulise.386969
McAfeeArtemis!1D14C9DE0B45
K7AntiVirusTrojan ( 0059a2701 )
K7GWTrojan ( 0059a2701 )
CyrenW64/Ipamor.A
SymantecTrojan.Gen.MBT
ESET-NOD32Win64/Filecoder.GG
TrendMicro-HouseCallTROJ_GEN.R011H0CK522
KasperskyTrojan-Dropper.Win32.Dycler.zrj
BitDefenderGen:Variant.Ulise.386969
CynetMalicious (score: 100)
AvastWin64:Trojan-gen
TencentWin32.Trojan-Dropper.Dycler.Ugil
Ad-AwareGen:Variant.Ulise.386969
EmsisoftGen:Variant.Ulise.386969 (B)
VIPREGen:Variant.Ulise.386969
SophosMal/Generic-S
APEXMalicious
GDataGen:Variant.Ulise.386969
JiangminTrojan.Blocker.urx
AviraTR/FileCoder.onxju
MAXmalware (ai score=81)
ArcabitTrojan.Ulise.D5E799
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R533023
ALYacGen:Variant.Ulise.386969
RisingRansom.Agent!8.6B7 (CLOUD)
IkarusTrojan-Ransom.FileCrypter
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen

How to remove Trojan-Dropper.Win32.Dycler.zrj?

Trojan-Dropper.Win32.Dycler.zrj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment