Trojan

Trojan-Downloader.Win32.Delf.xa information

Malware Removal

The Trojan-Downloader.Win32.Delf.xa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Delf.xa virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Delf.xa?


File Info:

name: 2BB819D5D79F6EE8FEC9.mlw
path: /opt/CAPEv2/storage/binaries/8a9a5d7d913f7f975c69a42b8f54a4ba73cf402d6b38eca2b374be3622950e54
crc32: B7F26D0A
md5: 2bb819d5d79f6ee8fec933e094a79773
sha1: 3790481c6311d9b103d2997a4855747f310b4b44
sha256: 8a9a5d7d913f7f975c69a42b8f54a4ba73cf402d6b38eca2b374be3622950e54
sha512: a574dcdf2998550c590bcc60c6fd4e9975f1d8e8af3c7460a0e250d358d484f00d9f915a60fadd21aac7fd318fda64d2c59b76767f395e39baf68a6f8f39369e
ssdeep: 768:mC+q5QIwbDzn2LY1JH6Jt9p26qh6omgzOx+i9K1Otpp5fucRqtKODN5ip5fucR9t:B+q5QJ6sTE2q8OvFr5WcUKODa5Wc20
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165A32813FBD1C475E4B2CB74ACB592606B377CA038A4473B6FA454EF1C61682AC487A6
sha3_384: 2081ff3d5e42e808eddb40fbf70f30eeedba0bbfd2539d46998547a589563f5e300cace5dc57be261146c4dc048390a7
ep_bytes: 558bec83c4e833c08945e88945ecb8e8
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Delf.xa also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader.7078
FireEyeGeneric.mg.2bb819d5d79f6ee8
SkyhighBehavesLike.Win32.Autorun.cz
McAfeeGenericRXVY-AQ!2BB819D5D79F
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.c6311d
BitDefenderThetaAI:Packer.B6751A621F
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Delf.xa
NANO-AntivirusTrojan.Win32.Delf.eflwsj
AvastWin32:Evo-gen [Trj]
F-SecureTrojan.TR/Dldr.Delphi.Gen
TrendMicroMal_Banld-1
Trapminemalicious.high.ml.score
SophosMal/DelpDldr-C
IkarusTrojan-Downloader.Win32.Banload
GDataWin32.Trojan.Agent.HB8Q0Y
JiangminTrojanDownloader.Delf.jo
GoogleDetected
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan[Downloader]/Win32.Delf
XcitiumTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
ViRobotTrojan.Win32.A.Downloader.55808.EP
ZoneAlarmTrojan-Downloader.Win32.Delf.xa
MicrosoftTrojan:Win32/Caynamer.A!ml
VaristW32/Delfloader.B.gen!Eldorado
AhnLab-V3Trojan/Win32.Banload.C20053
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Banld-1
RisingTrojan.DL.Banload.tg (CLASSIC)
YandexTrojan.GenAsa!e7z/i4R4bXo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.UCL!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Delf.xa?

Trojan-Downloader.Win32.Delf.xa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment