Trojan

Should I remove “Win32/TrojanDownloader.Delf.CBP”?

Malware Removal

The Win32/TrojanDownloader.Delf.CBP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.CBP virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/TrojanDownloader.Delf.CBP?


File Info:

crc32: 5A5CD845
md5: 916989035c6fc18eb44d603596cf9538
name: 916989035C6FC18EB44D603596CF9538.mlw
sha1: 6d5f936babb65025f4813b872ec0f1d9f5445b61
sha256: d757c641cca8089e15e196710a6f8346b280c2c78ce0048ad3a0319940d01704
sha512: 4a3fc37a9fd1a31b745c98eb8b5553d406b725b8c0536ab486bb044ec243ae019726de28f38702b92e42cc3e759d70d7f20196403bbf7982256692d9f743e6ae
ssdeep: 12288:cIFpx7ZJJk0FrdbGXP38y5mGv7igRcWDZJh+Da/78GPhA/b9zJg80ZjfY:tFtJJ9rc3X2fUMDC78GJiqRfY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 1984-2016 Adobe Systems Incorporated and its licensors. All rights reserved.
InternalName: Adobe Acrobat Reader DX
FileVersion: 10.7.20033.13760
ProductName: Adobe Acrobat Reader DX
ProductVersion: 10.7.20033.13760
FileDescription: Adobe Acrobat Reader DX
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

Win32/TrojanDownloader.Delf.CBP also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jacard.13238
FireEyeGen:Variant.Jacard.13238
ALYacGen:Variant.Jacard.13238
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 004e02ad1 )
BitDefenderGen:Variant.Jacard.13238
K7GWTrojan-Downloader ( 004e02ad1 )
Cybereasonmalicious.35c6fc
BitDefenderThetaAI:Packer.E19542C118
CyrenW32/Trojan.CTUT-7366
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CBP
APEXMalicious
AvastWin32:Delf-UFQ [Trj]
KasperskyTrojan-Downloader.Win32.Rakhni.ksr
AlibabaTrojanDownloader:Win32/Rakhni.093ff088
NANO-AntivirusTrojan.Win32.Rakhni.enmngk
AegisLabTrojan.Win32.Rakhni.a!c
TencentWin32.Trojan.Falsesign.Hrev
Ad-AwareGen:Variant.Jacard.13238
SophosMal/Generic-S
ComodoMalware@#2av2bs6sr5949
F-SecureTrojan.TR/Downloader.Gen7
DrWebTrojan.DownLoader24.62972
TrendMicroTROJ_ZUSY_GD10023A.UVPM
McAfee-GW-EditionGenericRXBF-GE!4BE6836118D3
EmsisoftGen:Variant.Jacard.13238 (B)
SentinelOneStatic AI – Malicious PE – Installer
JiangminTrojanDownloader.Rakhni.fd
AviraTR/Downloader.Gen7
Antiy-AVLTrojan[Downloader]/Win32.Rakhni
MicrosoftTrojanDownloader:Win32/Gendwnurl!rfn
ArcabitTrojan.Jacard.D33B6
AhnLab-V3Downloader/Win32.Delf.C1783347
ZoneAlarmTrojan-Downloader.Win32.Rakhni.ksr
GDataGen:Variant.Jacard.13238
CynetMalicious (score: 85)
McAfeeGenericRXAA-AA!916989035C6F
MAXmalware (ai score=88)
VBA32TScope.Trojan.Delf
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_ZUSY_GD10023A.UVPM
RisingDownloader.Gendwnurl!8.D8D6 (CLOUD)
YandexTrojan.GenAsa!VhAlGrfMo8k
IkarusTrojan-Downloader.Win32.Rakhni
FortinetW32/Dloader.CDW!tr
AVGWin32:Delf-UFQ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.f18

How to remove Win32/TrojanDownloader.Delf.CBP?

Win32/TrojanDownloader.Delf.CBP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment