Trojan

Win32/TrojanDownloader.Delf.CZJ removal tips

Malware Removal

The Win32/TrojanDownloader.Delf.CZJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.CZJ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

cdn.discordapp.com

How to determine Win32/TrojanDownloader.Delf.CZJ?


File Info:

crc32: CEA6DC0F
md5: 3b29490d1d4fabf5ab9322dcd69ca1fe
name: offer order.exe
sha1: 71f8280da4f7f87194358e92518ae593ff90bff8
sha256: e01b79e0c73e76e98ddca8c03d801e1742eeb3fec251b17162ef899332a12963
sha512: 9a612be2203994f588f8e660d25088021f5a67493db37099d0b99514402402bccd9b2ac3a11cf80af11987dd7c85bf91ce546ad9fec39c3f74f9cc428ea471da
ssdeep: 24576:0rZPUzSR2GihjQuUziUoNe6ZgMlXIqOUArsqmyiSCyiSVUJEq7zvVJf9w9:0rKzOC5UztWZVhlZfyiSCyiSV/CznFw9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Win32/TrojanDownloader.Delf.CZJ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34346756
FireEyeGeneric.mg.3b29490d1d4fabf5
CAT-QuickHealTrojanDropper.Dapato
ALYacTrojan.GenericKD.34346756
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
AegisLabTrojan.Win32.Dapato.b!c
K7AntiVirusTrojan-Downloader ( 0056c7381 )
BitDefenderTrojan.GenericKD.34346756
K7GWTrojan-Downloader ( 0056c7381 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroPUA.Win32.Caynamer.USXVPHD20
BitDefenderThetaGen:NN.ZelphiF.34152.3H3@aOLXFEoi
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.gen
AlibabaTrojanDownloader:Win32/Ymacco.140f06e5
Ad-AwareTrojan.GenericKD.34346756
ComodoTrojWare.Win32.Agent.gnvgs@0
F-SecureHeuristic.HEUR/AGEN.1114882
DrWebTrojan.PWS.Siggen2.53381
Invinceaheuristic
FortinetW32/Delf.BZL!tr
SophosMal/Generic-S
IkarusTrojan.Inject
JiangminTrojanDropper.Dapato.acag
AviraHEUR/AGEN.1114882
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Win32.Delf
ArcabitTrojan.Generic.D20C1704
ViRobotTrojan.Win32.Z.Agent.1951858
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.gen
MicrosoftTrojan:Win32/Ymacco.AAE0
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R347077
McAfeeFareit-FVM!3B29490D1D4F
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.MalPack.SMY
PandaTrj/GdSda.A
ESET-NOD32Win32/TrojanDownloader.Delf.CZJ
TrendMicro-HouseCallPUA.Win32.Caynamer.USXVPHD20
RisingTrojan.Kryptik!1.C56D (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataTrojan.GenericKD.34346756
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.Dropper.9f4

How to remove Win32/TrojanDownloader.Delf.CZJ?

Win32/TrojanDownloader.Delf.CZJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment