Trojan

Should I remove “Win32/TrojanDownloader.Delf.CYK”?

Malware Removal

The Win32/TrojanDownloader.Delf.CYK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.CYK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Win32/TrojanDownloader.Delf.CYK?


File Info:

name: 23FA47D1C4F4AB3084B9.mlw
path: /opt/CAPEv2/storage/binaries/0efa7703690d3fe9df70c81d7dea974aa710c7c55a76fd50e6a050bc76698d89
crc32: B0C70DBB
md5: 23fa47d1c4f4ab3084b9bd6ea926bb16
sha1: 26e854c6a1ee7af3f8a282caf06610b76ce21db9
sha256: 0efa7703690d3fe9df70c81d7dea974aa710c7c55a76fd50e6a050bc76698d89
sha512: 4be080d2a86c01dd084dcbf4a4fcc7bfd5457f75d5fecbb70092b5703fee6f94f4a5aeda4831272eee19a346eb5ee96475af787fa45ad90be49e007bd68bd8a9
ssdeep: 24576:sEWNeUebPnGhlh40zI+N//y8QNvMMl8XZf1CDRX1/4LsD+zVxuTBqS:jXVnx3b8ouLsD7YS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C35BF32B1A11A76C113093D7D1F53A99A27FE611FAEEB8267F51D0C8D7A1827C38187
sha3_384: d171d72a77fc966e999d42b1e68553bff8f1e4f52ff203ff635c3de60af81e39909f1365fda3d58fb931b04c82eb727d
ep_bytes: 558bec83c4f0b8644a4900e86c0ff7ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/TrojanDownloader.Delf.CYK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34164933
CAT-QuickHealTrojan.GenericIH.S15074032
McAfeeGenericRXAA-FA!23FA47D1C4F4
CylanceUnsafe
ZillyaBackdoor.Remcos.Win32.2770
SangforBackdoor.Win32.Remcos.gen
K7AntiVirusTrojan-Downloader ( 0056a8b01 )
AlibabaBackdoor:Win32/Tnega.821560f6
K7GWTrojan-Downloader ( 0056a8b01 )
Cybereasonmalicious.1c4f4a
CyrenW32/Delf_Troj.T2.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Delf.CYK
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.34164933
NANO-AntivirusTrojan.Win32.Remcos.hnsynn
AvastWin32:Malware-gen
RisingTrojan.Delf!1.C901 (CLASSIC)
Ad-AwareTrojan.GenericKD.34164933
SophosMal/Generic-R + Troj/Steale-AEN
ComodoMalware@#ga81ji2x3tlx
DrWebTrojan.DownLoader33.63862
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Rootkit.th
FireEyeGeneric.mg.23fa47d1c4f4ab30
EmsisoftTrojan.GenericKD.34164933 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Remcos.cay
AviraTR/Dldr.Delf.wlsbh
Antiy-AVLTrojan/Generic.ASMalwS.30B5A57
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tnega!MSR
GDataTrojan.GenericKD.34164933
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4159902
BitDefenderThetaGen:NN.ZelphiF.34294.eLX@aObkJDci
ALYacTrojan.GenericKD.34164933
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.SMY
TencentMalware.Win32.Gencirc.10cddeeb
YandexTrojan.Igent.bT47KP.1
IkarusTrojan.Inject
MaxSecureTrojan.Malware.9833444.susgen
FortinetW32/GenKryptik.EKLE!tr
WebrootW32.Trojan.GenKD
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDownloader.Delf.CYK?

Win32/TrojanDownloader.Delf.CYK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment