Trojan

What is “Win32/TrojanDownloader.Delf.AXK”?

Malware Removal

The Win32/TrojanDownloader.Delf.AXK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.AXK virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Win32/TrojanDownloader.Delf.AXK?


File Info:

name: C5DCF3E8695BE0910C04.mlw
path: /opt/CAPEv2/storage/binaries/6d9b92ffc0da86adc74a40b5bd00dfb587308928caa0bfb83e3ad3af4c0e3c86
crc32: C4CEC9B6
md5: c5dcf3e8695be0910c040ec770944964
sha1: 61946decf1c5cf39cea34f5f81c3362970eea6c2
sha256: 6d9b92ffc0da86adc74a40b5bd00dfb587308928caa0bfb83e3ad3af4c0e3c86
sha512: 60539d491118fa59c92d53685a8669eca2acec744d05f907ef476eaf5c09760c8f2bac163f0ef8e1a6e0d0c2a2f975c5a4c5b6077f85d25eae3f8e6e063ba4af
ssdeep: 3072:UDQkrZoosbIfXJhs9WbrXALvzDU6K5nvbc2tRF+CY2cMPnDCj:UDpoeV/AbP2tRF166DCj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EF3E0513BE2D0A5E46609710DF2E6B5D7FAAE002C25740B3BE0FF6BB9304B5D806E56
sha3_384: f78712de94ce8495401663eaaf1918c9b8cdc37b9605f539ef45c7ebc9ace5944e46a60a7b87a645702b5a6860f49bcc
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-05-11 20:03:36

Version Info:

CompanyName: Apple Inc.
FileDescription: iTunes Installer
FileVersion: 11.1.5.5
LegalCopyright: © Apple Inc. All Rights Reserved.
ProductName: iTunes
ProductVersion: 11.1.5.5
Translation: 0x0000 0x04e4

Win32/TrojanDownloader.Delf.AXK also known as:

LionicTrojan.Win32.Inject.4!c
DrWebTrojan.PWS.Banker1.15089
MicroWorld-eScanTrojan.NSIS.Androm.6
FireEyeTrojan.NSIS.Androm.6
McAfeeArtemis!C5DCF3E8695B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Injector.BRLE
K7AntiVirusTrojan ( 0055e3991 )
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.8695be
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Delf.AXK
TrendMicro-HouseCallTROJ_AGENT.YMNEV
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Inject.sbis
BitDefenderTrojan.NSIS.Androm.6
NANO-AntivirusTrojan.Win32.Banker1.dlawix
EmsisoftTrojan.NSIS.Androm.6 (B)
ComodoMalware@#m0v5vp8izoxc
TrendMicroTROJ_AGENT.YMNEV
McAfee-GW-EditionPWSZbot-FAGG!42E4078C829A
SophosGeneric ML PUA (PUA)
Paloaltogeneric.ml
GDataTrojan.NSIS.Androm.6
AviraTR/Inject.Gen
ZoneAlarmTrojan.Win32.Inject.sbis
MicrosoftVirTool:Win32/DelfInject.gen!BI
CynetMalicious (score: 100)
VBA32Trojan.Inject
MAXmalware (ai score=81)
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingTrojan.Skeeyah!8.3A6 (CLOUD)
YandexTrojan.Injector!jaEAoHfnFJQ
eGambitGeneric.Malware
FortinetW32/Kryptik.CKFX!tr
WebrootW32.Trojan.GenKD
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/TrojanDownloader.Delf.AXK?

Win32/TrojanDownloader.Delf.AXK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment