Trojan

Should I remove “Win32/TrojanDownloader.Delf.BQX”?

Malware Removal

The Win32/TrojanDownloader.Delf.BQX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.BQX virus can do?

  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/TrojanDownloader.Delf.BQX?


File Info:

name: 996C6DDF125331A08D52.mlw
path: /opt/CAPEv2/storage/binaries/d526b2ae5a81a3bfe28bb8ea91cfb53b0e56293c4e78715c25b55960acfef5a0
crc32: BB20D14A
md5: 996c6ddf125331a08d5277d3410bc8bd
sha1: 064d53315789fb3ab367cd9d049118d58653ff20
sha256: d526b2ae5a81a3bfe28bb8ea91cfb53b0e56293c4e78715c25b55960acfef5a0
sha512: 1115714096dfc3c6e846783c36e3953c1684d9bc76f572a90a0432d3959a2dd6ca386f2291ca0cc4d5c34dd55cea8c178012ec5a0f76927a67f7effa98d4f6bf
ssdeep: 3072:w8+TYxu69bYTd6fdF0Yyow888888888888W88888888888:w8+OdTa9888888888888W88888888888
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4D3B313A3C3047EE569063B787590C4ECFFF97928D624265DB5FA0E08BC59318BAA53
sha3_384: 2b0b2d292bf8451f55cdfacd147ea9943ce1c416cf711a74e48bb84644a179cdaf61d1297d44f671f6f758946d4fdd01
ep_bytes: 558becb9060000006a006a004975f953
timestamp: 2016-02-14 23:44:30

Version Info:

0: [No Data]

Win32/TrojanDownloader.Delf.BQX also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Heur.Mint.Porcupine.iGW@bujYb2aig
FireEyeGeneric.mg.996c6ddf125331a0
McAfeeGenericR-FZH!996C6DDF1253
CylanceUnsafe
ZillyaDownloader.Delf.Win32.46880
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaTrojanDownloader:Win32/Porcupine.82aafe6a
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZelphiF.34084.iGW@aujYb2ai
CyrenW32/Trojan.NRVD-2442
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.BQX
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Heur.Mint.Porcupine.iGW@bujYb2aig
NANO-AntivirusTrojan.Win32.Delf.eawkhc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114c2714
Ad-AwareGen:Heur.Mint.Porcupine.iGW@bujYb2aig
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Infected.cm
EmsisoftGen:Heur.Mint.Porcupine.iGW@bujYb2aig (B)
IkarusTrojan-Downloader.Win32.Delf
GDataGen:Heur.Mint.Porcupine.iGW@bujYb2aig
JiangminTrojanDownloader.Generic.aqyf
AviraTR/Dldr.Delphi.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.1771E75
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Mint.Porcupine.E663BD
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Agent.C1327037
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Heur.Mint.Porcupine.iGW@bujYb2aig
MalwarebytesMachineLearning/Anomalous.95%
APEXMalicious
RisingTrojan.DL.Win32.Condirx.bu (CLASSIC)
YandexTrojan.GenAsa!9j8/W27NspM
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic.BQX!tr.dldr
AVGWin32:Malware-gen
Cybereasonmalicious.f12533
PandaTrj/GdSda.A

How to remove Win32/TrojanDownloader.Delf.BQX?

Win32/TrojanDownloader.Delf.BQX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment