Trojan

Should I remove “Win32/TrojanDownloader.Delf.BYK”?

Malware Removal

The Win32/TrojanDownloader.Delf.BYK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.BYK virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Win32/TrojanDownloader.Delf.BYK?


File Info:

crc32: E807AEB4
md5: 301b96a5f61337d42f7294f6c324f307
name: 301B96A5F61337D42F7294F6C324F307.mlw
sha1: 65bff914013f66896c36beff0af37d56ac11f2b6
sha256: 5b50956a6d103a62a3ed1a380c1d59e17c036f0e1206b97665136b3ec76f31bf
sha512: eddf067ce321b616b605be331d8019aba1a0dc6fc0f6d71d5accdf0babb34a8fda0b4caf69edf654d447819cf5ccb653fc3505a6449451e9535160887ad77c80
ssdeep: 24576:v24gsa6Qb1kXGxFAAhQhwszIHSQYf9XK5SDFiZY:+4gsvQb1k28nws0H+9XK4DFiW
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 1984-2016 Adobe Systems Incorporated and its licensors. All rights reserved.
InternalName: Adobe Acrobat Reader DX
FileVersion: 10.7.20033.13742
ProductName: Adobe Acrobat Reader DX
ProductVersion: 10.7.20033.13742
FileDescription: Adobe Acrobat Reader DX
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

Win32/TrojanDownloader.Delf.BYK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jacard.13238
FireEyeGeneric.mg.301b96a5f61337d4
ALYacGen:Variant.Jacard.13238
CylanceUnsafe
ZillyaTrojan.Bcex.Win32.361
AegisLabTrojan.Win32.Bcex.4!c
K7AntiVirusTrojan-Downloader ( 004e02ad1 )
BitDefenderGen:Variant.Jacard.13238
K7GWTrojan-Downloader ( 004e02ad1 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Rakhni.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Hesv.hkt
NANO-AntivirusTrojan.Win32.Bcex.emtugk
AvastWin32:Delf-UFQ [Trj]
TencentMalware.Win32.Gencirc.10b3a92b
Ad-AwareGen:Variant.Jacard.13238
EmsisoftGen:Variant.Jacard.13238 (B)
ComodoMalware@#2haocll4pmxg5
F-SecureTrojan.TR/Downloader.Gen7
DrWebTrojan.DownLoader24.62972
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXBB-LA!7424236ADD22
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Rakhni
JiangminTrojan.Bcex.jt
AviraTR/Downloader.Gen7
eGambitUnsafe.AI_Score_90%
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Bcex
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Jacard.D33B6
ZoneAlarmTrojan.Win32.Hesv.hkt
GDataGen:Variant.Jacard.13238
CynetMalicious (score: 85)
AhnLab-V3Downloader/Win32.Delf.C1783347
McAfeeGenericRXAA-FA!301B96A5F613
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Trojan.Malicious.DDS
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.BYK
RisingDownloader.Gendwnurl!8.D8D6 (TFE:4:D0eVNMP45xB)
YandexTrojan.GenAsa!B4SWzjBtgJ4
SentinelOneStatic AI – Suspicious PE – Installer
FortinetW32/Dloader.CDW!tr
BitDefenderThetaAI:Packer.E19542C118
AVGWin32:Delf-UFQ [Trj]
Cybereasonmalicious.5f6133
PandaTrj/Genetic.gen
Qihoo-360Win32/Trojan.f18

How to remove Win32/TrojanDownloader.Delf.BYK?

Win32/TrojanDownloader.Delf.BYK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment