Trojan

Trojan.Win32.Cosmu.dleo removal tips

Malware Removal

The Trojan.Win32.Cosmu.dleo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cosmu.dleo virus can do?

  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Cosmu.dleo?


File Info:

crc32: 6E7F86C0
md5: 9686c792a8f749ceb0aa5d66202fc079
name: 9686C792A8F749CEB0AA5D66202FC079.mlw
sha1: f01d9354dd44e54dbf3eb957bb58a2659405150a
sha256: bb08cc9cfdfeebf1c55bf72909a0b5feac87494d6d0cbdd25b0e91968258952d
sha512: fc257f5d1ff262f4c9896b26808ae663aacdc4148d56b9f2dd01b4f5bc772542a2e1bcb8d2849cd19a640afbae75fd20966200faa0561a5019ab5c06f1abaea7
ssdeep: 1536:0l8D3F1J+KLGSDxdGPPli8fDAHiTXLPQGj6EeIAchhsfjGj93G58f98kj:0m1OKLFDX6lfMHGjjdZSfjCq8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Cosmu.dleo also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050f06c1 )
LionicTrojan.Win32.Cosmu.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5342
ClamAVWin.Trojan.Agent-1884099
ALYacTrojan.Ransom.RotorCrypt
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.14965
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Cosmu.b76d4042
K7GWTrojan ( 0050f06c1 )
Cybereasonmalicious.2a8f74
SymantecRansom.Kovter
ESET-NOD32a variant of Win32/Filecoder.RotoCrypt.C
APEXMalicious
AvastWin32:KadrBot [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Cosmu.dleo
BitDefenderGen:Variant.Ransom.RotorCrypt.8
NANO-AntivirusTrojan.Win32.Crypted.ehyqeo
MicroWorld-eScanGen:Variant.Ransom.RotorCrypt.8
TencentWin32.Trojan.Cosmu.Htvq
Ad-AwareGen:Variant.Ransom.RotorCrypt.8
SophosMal/Generic-S + Troj/Kryptik-IZ
ComodoMalware@#ikfn4wpxk9xf
BitDefenderThetaAI:Packer.A7C72B8C1E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_ROTOCRYPT.A
McAfee-GW-EditionGenericRXHB-KI!9686C792A8F7
FireEyeGeneric.mg.9686c792a8f749ce
EmsisoftGen:Variant.Ransom.RotorCrypt.8 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cosmu.na
AviraTR/Crypt.XPACK.Gen2
MicrosoftVirTool:Win32/Aicat.A!ml
GDataGen:Variant.Ransom.RotorCrypt.8
AhnLab-V3Trojan/Win32.Ransom.R230222
McAfeeGenericRXHB-KI!9686C792A8F7
MAXmalware (ai score=100)
VBA32Trojan.Cosmu
PandaGeneric Suspicious
TrendMicro-HouseCallRansom_ROTOCRYPT.A
RisingTrojan.Generic@ML.100 (RDML:G6hRX4GXoJqfDCmkQO7V/Q)
YandexTrojan.Cosmu!O50+1dYNEcs
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/RotoCrypt.C!tr
AVGWin32:KadrBot [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Cosmu.HxQBuIEA

How to remove Trojan.Win32.Cosmu.dleo?

Trojan.Win32.Cosmu.dleo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment