Trojan

What is “Trojan.Win32.SelfDel.ijyb”?

Malware Removal

The Trojan.Win32.SelfDel.ijyb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.SelfDel.ijyb virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.SelfDel.ijyb?


File Info:

name: D916DD8F45383001E139.mlw
path: /opt/CAPEv2/storage/binaries/d5ae99831879fcdee9e3bf2bd82abb49f36d93810894bfc05eacf82b59805fcd
crc32: 5AFBD5FE
md5: d916dd8f45383001e13990981d314b1a
sha1: 7baa56f6f697012ac0794665d04ba5bfcbc25325
sha256: d5ae99831879fcdee9e3bf2bd82abb49f36d93810894bfc05eacf82b59805fcd
sha512: b1b6745c3ff21d9843177764f11081bed50ad649ee47dc42d8afa5e72c060328d425f122183afc191cc35c96df76aafc999e578ec2e9faec5001080e4a4b8cc8
ssdeep: 24576:XadMv6CYrjqnyLQDsxXjZFcoX71V/Zf8dRn:XnvyjdLQKSoX7bW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA45D012F7C6C0F6D99278B11D2BF326AB3569194322C88BABE13F768E31101573676D
sha3_384: 23191c5e3a0b3a1eab338febe5a951168e2b69d8674f6602d7a4415b225d47d5a53fd6d975f54a26a416b196f6d36417
ep_bytes: e8a7c00000e979feffffcccccccccccc
timestamp: 2010-02-28 16:59:51

Version Info:

FileVersion: 3.3.5.6
Comments: 华中作品
FileDescription: 华中作品
Translation: 0x0804 0x04b0

Trojan.Win32.SelfDel.ijyb also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.SelfDel.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.69909152
FireEyeTrojan.GenericKD.69909152
SkyhighBehavesLike.Win32.BadFile.tc
McAfeeArtemis!D916DD8F4538
VIPRETrojan.GenericKD.69909152
SangforTrojan.Win32.SelfDel.Vnao
BitDefenderTrojan.GenericKD.69909152
Cybereasonmalicious.6f6970
Elasticmalicious (moderate confidence)
APEXMalicious
KasperskyTrojan.Win32.SelfDel.ijyb
AlibabaTrojan:Win32/SelfDel.87bcd674
SophosMal/Generic-S
F-SecureTrojan.TR/SelfDel.ltfzu
TrendMicroTROJ_GEN.R002C0XJO23
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.69909152 (B)
GoogleDetected
AviraTR/SelfDel.ltfzu
VaristW32/AutoIt.WH.gen!Eldorado
Kingsoftmalware.kb.a.960
ArcabitTrojan.Generic.D42ABAA0
ZoneAlarmTrojan.Win32.SelfDel.ijyb
GDataTrojan.GenericKD.69909152
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.69909152
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
TrendMicro-HouseCallTROJ_GEN.R002C0XJO23
TencentWin32.Trojan.Selfdel.Vimw
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Pioneer.H
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Win32.SelfDel.ijyb?

Trojan.Win32.SelfDel.ijyb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment