Trojan

Win32/TrojanDownloader.Delf.CBT removal guide

Malware Removal

The Win32/TrojanDownloader.Delf.CBT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.CBT virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/TrojanDownloader.Delf.CBT?


File Info:

crc32: 9A691E3C
md5: 0428114fc1d2942a0364cfeb6343e42d
name: 0428114FC1D2942A0364CFEB6343E42D.mlw
sha1: a4f2ea98cfa101a4f1d4fe7978d96c44ee9a3762
sha256: dd7ddd6af002c653565c90de4706b1bbbcd94830a50bb69a100fd35d4b36f186
sha512: c347ba098e3ec32a082829c73f028556866358f11492273a688213a31b2d613d9b51ebe7ba4987ed89989e96f73c49b39cd770e0cea4a98c35a98028e1bfc867
ssdeep: 24576:TPh7TIoZxB+nUa8Xhik73oGWKWN9d8r3XYsSzApwecNzEyXrPlo:TVjZ/79wKYT8rrSu1
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 1984-2017 Adobe Systems Incorporated and its licensors. All rights reserved.
InternalName: Adobe Acrobat Reader DX
FileVersion: 10.7.20033.13800
ProductName: Adobe Acrobat Reader DX
ProductVersion: 10.7.20033.13800
FileDescription: Adobe Acrobat Reader DX
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

Win32/TrojanDownloader.Delf.CBT also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jacard.13238
FireEyeGeneric.mg.0428114fc1d2942a
Qihoo-360Win32/Trojan.Adware.37e
McAfeeArtemis!0428114FC1D2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Rakhni.a!c
K7AntiVirusTrojan-Downloader ( 004e02ad1 )
BitDefenderGen:Variant.Jacard.13238
K7GWTrojan-Downloader ( 004e02ad1 )
Cybereasonmalicious.fc1d29
CyrenW32/Trojan.CTUT-7366
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Delf-UFQ [Trj]
CynetMalicious (score: 85)
KasperskyTrojan-Downloader.Win32.Rakhni.kws
NANO-AntivirusTrojan.Win32.Rakhni.eqbdoo
RisingDownloader.Gendwnurl!8.D8D6 (TFE:4:qVkld1lAcPC)
Ad-AwareGen:Variant.Jacard.13238
SophosMal/Generic-S
ComodoMalware@#f62na7b30nue
F-SecureTrojan.TR/Downloader.Gen7
DrWebTrojan.DownLoader24.62972
ZillyaDownloader.Rakhni.Win32.287
McAfee-GW-EditionGenericRXBO-ZK!F5F12302C774
EmsisoftGen:Variant.Jacard.13238 (B)
SentinelOneStatic AI – Malicious PE – Installer
JiangminTrojanDownloader.Rakhni.gb
AviraTR/Downloader.Gen7
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Win32.Rakhni
MicrosoftTrojanDownloader:Win32/Gendwnurl!rfn
ArcabitTrojan.Jacard.D33B6
ZoneAlarmTrojan-Downloader.Win32.Rakhni.kws
GDataGen:Variant.Jacard.13238
AhnLab-V3Downloader/Win32.Delf.C1783347
BitDefenderThetaAI:Packer.E19542C118
ALYacGen:Variant.Jacard.13238
VBA32TScope.Trojan.Delf
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CBT
TencentMalware.Win32.Gencirc.10bb3b07
YandexTrojan.GenAsa!VhAlGrfMo8k
IkarusTrojan-Downloader.Win32.Rakhni
eGambitUnsafe.AI_Score_64%
FortinetW32/Agent.BYK!tr.dldr
AVGWin32:Delf-UFQ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/TrojanDownloader.Delf.CBT?

Win32/TrojanDownloader.Delf.CBT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment