Backdoor

Backdoor:Win32/Delf.ZSU (file analysis)

Malware Removal

The Backdoor:Win32/Delf.ZSU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Delf.ZSU virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Delf.ZSU?


File Info:

name: CA5DA821CEED929124A8.mlw
path: /opt/CAPEv2/storage/binaries/b703a48d7e9e556872fd2c7ddc616e23291332130728725127ce8678fea714ea
crc32: 8C8028CD
md5: ca5da821ceed929124a82681faf20568
sha1: 016f19c5a16c4a66600f2457e8c19abe95d8e9f6
sha256: b703a48d7e9e556872fd2c7ddc616e23291332130728725127ce8678fea714ea
sha512: 9401a73e0f3f8134ec2a0a370f6a944968dd787238bd633550d71dd9e84c474ae470858b9e7c345073f6278aa10b57e86cce4fb9a7d4821cc74ebd0acda03bd7
ssdeep: 384:SceyRGmEUsLmPKb4kApw4ERNuIS3xwz+04aQCdnGn/61BZctIsp88UhO7HlPq0K5:NDEyPKU2jWIYwznrGy7oLi8UirMZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119D21A56FA90C473D061C9FC4C0BC1AAB75B75343E7818A67AE95FCDDA3A2C28A1C543
sha3_384: 85b9e3dfa2efe5b7ec7a481d744ac0c47bd36fdef3e1f61d23cee8108b06d2b2698355385256341cabfcc436a4af5fbc
ep_bytes: 558becb9100000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Delf.ZSU also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.Delf.R
McAfeePWS-Zbot-FBAM!CA5DA821CEED
ZillyaTrojan.Agent.Win32.86200
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.1ceed9
VirITTrojan.Win32.Generic.CGC
CyrenW32/Rbot.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/SlhBack.H
APEXMalicious
ClamAVWin.Trojan.Agent-47467
KasperskyTrojan.Win32.Agent.bkj
BitDefenderTrojan.Crypt.Delf.R
NANO-AntivirusTrojan.Win32.Agent.einoop
AvastWin32:Agent-LRX [Trj]
SophosML/PE-A + Troj/Agent-GCY
ComodoTrojWare.Win32.TrojanDownloader.Delf.~MR@1b9ms
DrWebTrojan.DownLoader.61337
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_AGENT_0000257.TOMA
McAfee-GW-EditionBehavesLike.Win32.Dropper.nh
FireEyeGeneric.mg.ca5da821ceed9291
EmsisoftTrojan.Crypt.Delf.R (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.sbg
AviraTR/Hijacker.Gen
Antiy-AVLTrojan/Generic.ASMalwS.DA288
MicrosoftBackdoor:Win32/Delf.ZSU
ViRobotTrojan.Win32.A.Agent.15973
GDataTrojan.Crypt.Delf.R
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.A3A8CEA721
ALYacTrojan.Crypt.Delf.R
MAXmalware (ai score=87)
VBA32Malware-Cryptor.Inject.gen
TrendMicro-HouseCallTROJ_AGENT_0000257.TOMA
RisingTrojan.Win32.Agent.vyb (CLOUD)
YandexTrojan.GenAsa!cJFDSLvsUNI
IkarusTrojan-PWS.Win32.OnLineGames
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.fam!tr
AVGWin32:Agent-LRX [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor:Win32/Delf.ZSU?

Backdoor:Win32/Delf.ZSU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment