Trojan

Trojan.Win32.Deshacop.yp (file analysis)

Malware Removal

The Trojan.Win32.Deshacop.yp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Deshacop.yp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Singapore)
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Trojan.Win32.Deshacop.yp?


File Info:

crc32: AA7FF98E
md5: 1f5ae445d7271c92f018763ebfd2bf1d
name: 1F5AE445D7271C92F018763EBFD2BF1D.mlw
sha1: bfdde4efbc2e0b0fb85e002a5473dbbdbbf7f28d
sha256: 0e09c6311fb22f71ec77b68624b082ef02f4ca2cec68d19cbe71e916ba02c9ec
sha512: 2b799727dc45c7687c07f23e90be4627f7ae0e33cd24afc650ba6cc291d2759eb8754735e2cd6b24b109039362b45573f41b634c6727e2fdc0d7c0755e542f44
ssdeep: 6144:hozMeGnlQmEBbzzP+SOQlkeI2NPmEIExdICt41s0zR8DUwtXC/+0:uzMeGnlWzv9lLlHt41s018QwtXC/+0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Leaves xa9 1911
InternalName: Methodologically
FileVersion: 234, 41, 188, 176
CompanyName: Philips PC Cameras
ProductName: Frontals Fenders
FileDescription: Hottempered
OriginalFilename: Leaps.exe

Trojan.Win32.Deshacop.yp also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004d41c61 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1751
CynetMalicious (score: 100)
CAT-QuickHealRansom.TeslaCrypt.WR4
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.193
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Deshacop.893883db
K7GWTrojan ( 004d41c61 )
Cybereasonmalicious.5d7271
SymantecPacked.Generic.490
ESET-NOD32Win32/Filecoder.TeslaCrypt.D
APEXMalicious
AvastWin32:Teerac-AC [Trj]
KasperskyTrojan.Win32.Deshacop.yp
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Deshacop.dvuayu
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.114c7b66
Ad-AwareTrojan.Cripack.Gen.1
SophosMal/Generic-R + Mal/Tinba-L
ComodoMalware@#1r93lgkq1xl15
BitDefenderThetaGen:NN.ZexaF.34628.vq3@aGVK1RmH
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_HpMyApp
McAfee-GW-EditionGenericR-OOF!1F5AE445D727
FireEyeGeneric.mg.1f5ae445d7271c92
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Deshacop.go
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1118878
eGambitGeneric.Malware
MicrosoftRansom:Win32/Tescrypt.C
ArcabitTrojan.Cripack.Gen.1
AegisLabTrojan.Win32.Deshacop.4!c
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeGenericR-OOF!1F5AE445D727
MAXmalware (ai score=100)
VBA32BScope.Trojan.Deshacop
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_HpMyApp
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!TZocd7SyAPs
IkarusTrojan.Win32.Filecoder
FortinetW32/Deshacop.XO!tr
AVGWin32:Teerac-AC [Trj]
Qihoo-360Win32/Ransom.Tescrypt.HwcBEpsA

How to remove Trojan.Win32.Deshacop.yp?

Trojan.Win32.Deshacop.yp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment