Trojan

Trojan.Win32.Dedok.amc removal guide

Malware Removal

The Trojan.Win32.Dedok.amc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Dedok.amc virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the embedded win api malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Dedok.amc?


File Info:

name: 1FA481A4C05C15EEE537.mlw
path: /opt/CAPEv2/storage/binaries/2e4d3bb081eca759d3a8aac068a806bcbfea5e73294fded13d44b6e22aeaab6f
crc32: D17CD9F6
md5: 1fa481a4c05c15eee5374cf857211923
sha1: 7da3757c9501e68fcc04f39011d925fb50b8d056
sha256: 2e4d3bb081eca759d3a8aac068a806bcbfea5e73294fded13d44b6e22aeaab6f
sha512: 1e9513b324776adcfc9626cd6277211993dafe3b2aeb6d17d3db9cfb12ebee946d3df757add8395f50aeb19ffe227737e0c4888f0e1edd4df22f2b93cc81dc9f
ssdeep: 196608:W5aF/doSaiuX1ZzJkq3Ipk8hbcpO5tyLmVelhGEXknb74LvFnv+y5x1hj86IiY6p:W5a5WSaiuPzizNx5emVelwUjhj3DimT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10DC63391B39315F8E8726F7314213760253AEFE91B671DD7EE84091A1CB32E1EA760D8
sha3_384: 7ba2c2603babdd051c66cc67fc03f6258b120d958e63102219a1b247b0476cdfdd6dcc909ab5caff5966b995f0feb037
ep_bytes: 558bec6aff6880fa410068f0c4410064
timestamp: 2016-04-02 22:14:34

Version Info:

0: [No Data]

Trojan.Win32.Dedok.amc also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dedok.4!c
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.1fa481a4c05c15ee
SkyhighBehavesLike.Win32.Generic.wc
McAfeeArtemis!1FA481A4C05C
Cylanceunsafe
SangforTrojan.Win32.Agent.Vuxc
Paloaltogeneric.ml
SymantecTrojan.Gen.MBT
CynetMalicious (score: 99)
ClamAVWin.Malware.Drivepack-9884589-1
KasperskyTrojan.Win32.Dedok.amc
F-SecureTrojan.TR/Patched.Gen2
TrendMicroTrojanSpy.Win32.RHADAMANTHYS.YXEEBZ
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GoogleDetected
AviraTR/Patched.Gen2
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmTrojan.Win32.Dedok.amc
VaristW32/Trojan.XQNF-5986
MaxSecureTrojan.Malware.3411146.susgen
FortinetNSIS/Injector.AOW!tr
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Dedok.amc?

Trojan.Win32.Dedok.amc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment