Trojan

Should I remove “TrojanDownloader:Win32/Delf.LZZ”?

Malware Removal

The TrojanDownloader:Win32/Delf.LZZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Delf.LZZ virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Delf.LZZ?


File Info:

name: 6CE294E040FFF86486C8.mlw
path: /opt/CAPEv2/storage/binaries/19ffbc25836ce49743a6f0d78315bc84a386930a2ece9aed3994efcc1355b100
crc32: 66FC747C
md5: 6ce294e040fff86486c84c10f3578c06
sha1: e0dc6d4375138ec957e9e70f1000f7905a14868a
sha256: 19ffbc25836ce49743a6f0d78315bc84a386930a2ece9aed3994efcc1355b100
sha512: 15766e4b89002326cf29375096fd2d1a0fe5b35d17c20460b3147de96e90fd5909799769f505cc49b96fea148e198a5028b6d1c81a5a28b1e99beddc9b1b5816
ssdeep: 6144:TBKHYmz6mq2pmHmFV2YjnWuwqzeRhvaw4G:04m5bpnL2KnEqCRhvaG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D154223B6AD78CE1E7890A3922504D1D833E5D4CB504C79722237DAE5AB0F6E95092BF
sha3_384: 99c7eb451b6cfc65d2492b406307366bf878eaaedbaefa2183c5c0e129699db8ac03da05a8160ebd03336831663a23c8
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2011-01-25 07:31:10

Version Info:

CompanyName:
FileDescription: 281600
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

TrojanDownloader:Win32/Delf.LZZ also known as:

LionicTrojan.Win32.Delf.lQdB
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.262536
FireEyeGeneric.mg.6ce294e040fff864
CAT-QuickHealTrojanDownloader.Delf.NK12
SkyhighBehavesLike.Win32.GenDownloader.dc
ALYacGen:Variant.Ursu.262536
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ursu.262536
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( f1000a011 )
BitDefenderGen:Variant.Ursu.262536
K7GWTrojan ( f1000a011 )
Cybereasonmalicious.375138
BitDefenderThetaGen:NN.ZelphiF.36792.rW1baWd4Kddj
VirITTrojan.Win32.Cryptic.CBE
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Delf.QEW
APEXMalicious
ClamAVWin.Packed.Delf-9786618-0
KasperskyTrojan-Downloader.Win32.Delf.aznp
AlibabaTrojanDownloader:Win32/GenDownloader.43af30c7
NANO-AntivirusTrojan.Win32.Delf.crlibp
ViRobotTrojan.Win32.A.Downloader.276472.A
RisingTrojan.DL.Win32.Undef.sua (CLOUD)
SophosMal/DelpDwnld-B
BaiduWin32.Trojan-Downloader.Agent.af
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.DownLoader4.5793
ZillyaDownloader.Delf.Win32.18627
TrendMicroTROJ_DLOADR.SMAI
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.262536 (B)
IkarusTrojan-Dropper.Delf
JiangminTrojanDownloader.Delf.aaad
WebrootW32.Delf.Gen
GoogleDetected
AviraTR/Dldr.Delphi.Gen
VaristW32/Delf.AI.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Delf
KingsoftWin32.Troj.Undef.a
MicrosoftTrojanDownloader:Win32/Delf.LZZ
XcitiumTrojWare.Win32.Downloader.Fraudload.AA@2vwxs7
ArcabitTrojan.Ursu.D40188
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmTrojan-Downloader.Win32.Delf.aznp
GDataGen:Variant.Ursu.262536
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Delf.R3483
McAfeeGenericRXAA-AA!6CE294E040FF
DeepInstinctMALICIOUS
VBA32TrojanDownloader.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DLOADR.SMAI
TencentTrojan.Win32.Downloader.tgv
YandexTrojan.GenAsa!dETtiKvSjKU
SentinelOneStatic AI – Suspicious PE
FortinetW32/Delf.QEW!tr.dldr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Delf.LZZ?

TrojanDownloader:Win32/Delf.LZZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment