Trojan

TrojanDownloader:Win32/Delf.ZXB removal tips

Malware Removal

The TrojanDownloader:Win32/Delf.ZXB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Delf.ZXB virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded pe malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Delf.ZXB?


File Info:

name: 664DFF6BF1F160FB7033.mlw
path: /opt/CAPEv2/storage/binaries/39c117cfae557a64f29f906294403df724385e1e7c5d5959b28d87f4c1a15ba5
crc32: 432E1682
md5: 664dff6bf1f160fb7033e1f49ad963ec
sha1: a9f5d402317651291a66472e13ed893319bcb2ce
sha256: 39c117cfae557a64f29f906294403df724385e1e7c5d5959b28d87f4c1a15ba5
sha512: 6b2d2b3941fe9562f08aed61814918ecf8ecf96e5e3c70ae8b3cc3ee2075314111c05169609af03df7c6350fd13675815cb802c8a84e6a9c82efe282106c9244
ssdeep: 12288:LroAeNXOsRbfEDHq1jUyE+RW9qEbRCS96jotA:LroBzfEDqlUDX9q2gSQj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5A46D22B3F14437C1336B7DCD5B96AC982A7E502D28A8467BF51D4C9F39781382B297
sha3_384: c98c1fa141f96b83317e07ba4b5a4ef9ae9b5121a5db64c34435ea346deed5d10476cf9bf4e91fe05da0aa4eee8247f6
ep_bytes: 558bec83c4f0b800384600e8442cfaff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: my
FileDescription: name is
FileVersion: 360
InternalName: 360
LegalCopyright: kkk
LegalTrademarks: sss
OriginalFilename: www
ProductName: uuuu
ProductVersion: xxxx
Comments: sss
wwww: wws
askdlasld: sys
dsdwowdw: tem
Translation: 0x0404 0x03b6

TrojanDownloader:Win32/Delf.ZXB also known as:

LionicTrojan.Win32.Agent.a!c
MicroWorld-eScanGen:Variant.Midie.115501
FireEyeGen:Variant.Midie.115501
CAT-QuickHealTrojan.Agent.A8
SkyhighBehavesLike.Win32.ObfuscatedPoly.gh
McAfeeGenericRXAA-AA!664DFF6BF1F1
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Agent.Win32.149310
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Kirly.77c02117
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
BaiduWin32.Trojan-Downloader.Agent.ad
VirITTrojan.Win32.Agent2.AJIH
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kirly.G
APEXMalicious
TrendMicro-HouseCallTROJ_DLDELF.SMIM
ClamAVWin.Downloader.103790-1
KasperskyTrojan.Win32.Agent.ided
BitDefenderGen:Variant.Midie.115501
NANO-AntivirusTrojan.Win32.Agent.coued
AvastWin32:Delf-OGT [Trj]
TencentTrojan.DL.Win32.Delf.bi
EmsisoftGen:Variant.Midie.115501 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoad2.47006
VIPREGen:Variant.Midie.115501
TrendMicroTROJ_DLDELF.SMIM
SophosMal/Generic-S
MAXmalware (ai score=100)
JiangminTrojanDownloader.Agent.cuoj
GoogleDetected
AviraTR/ATRAPS.Gen
VaristW32/Delf.AM.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Agent
KingsoftWin32.Trojan.Agent.ided
MicrosoftTrojanDownloader:Win32/Delf.ZXB
XcitiumTrojWare.Win32.Downloader.Agent.fvoi@4nxkk6
ArcabitTrojan.Midie.D1C32D
ViRobotTrojan.Win32.Downloader.Gen.J
ZoneAlarmTrojan.Win32.Agent.ided
GDataGen:Variant.Midie.115501
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Agent.R3506
BitDefenderThetaAI:Packer.C724852019
ALYacGen:Variant.Midie.115501
TACHYONTrojan-Downloader/W32.DP-Agent.489472.B
VBA32BScope.TrojanDownloader.Adload
Cylanceunsafe
PandaTrj/Downloader.YCA
RisingTrojan.Win32.Fednu.vo (CLASSIC)
YandexTrojan.DL.Agent!rYQAMOdZrqg
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.FVOI!tr.dldr
AVGWin32:Delf-OGT [Trj]
Cybereasonmalicious.bf1f16
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Kirly.G

How to remove TrojanDownloader:Win32/Delf.ZXB?

TrojanDownloader:Win32/Delf.ZXB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment