Trojan

Win32/TrojanDownloader.Delf_AGen.D malicious file

Malware Removal

The Win32/TrojanDownloader.Delf_AGen.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf_AGen.D virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Portuguese (Brazil)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Delf_AGen.D?


File Info:

name: E44CCB84DD2294166AE8.mlw
path: /opt/CAPEv2/storage/binaries/cb1d05d68d63382c037204a028e470848f17904e0de53a261827ce0ef963dce2
crc32: A9550890
md5: e44ccb84dd2294166ae8362e40befb61
sha1: a4b1e2dd3d29abac270be8cc684f704b5506458a
sha256: cb1d05d68d63382c037204a028e470848f17904e0de53a261827ce0ef963dce2
sha512: 35b7b6cf83df0569b7be2e55b58078c238a300a813ea27f81766206b3ade7b521fdc1539213e682a83ce0387ca2cdf5d275abd537a1516544fcc8de852a62955
ssdeep: 49152:VjJeMMO/6kl2tbZ9ASy/yA08yBKYsqLEMvK6Ht4d58qIkUiJpV2die9TdTjcK8gv:VjJerFbgIBKYsqLEYi8qtY1fcd9K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DD366E12B285553AD07B0E37483BE758593B7E702A19CCDB37E81E8C4F3A5416A3AB47
sha3_384: 8da2c23bf49e9740b3b21590ec3533036fdd7aa25666ea746af1ca0efa365ed549c52b2bbfc95ba67b55e471fa399909
ep_bytes: 558bec83c4f0b8c4507c00e894b6c2ff
timestamp: 2022-01-31 15:43:10

Version Info:

CompanyName: PDF Allaaambrinodes
FileDescription: PDF Allaaambrinodes
FileVersion: 1.79.6.2
InternalName: PDF Allaaambrinodes
LegalCopyright: PDF Allaaambrinodes
LegalTrademarks: PDF Allaaambrinodes
OriginalFilename: PDF Allaaambrinodes
ProgramID: PDF Allaaambrinodes
ProductName: PDF Allaaambrinodes
ProductVersion: 1.79.6.2
Comments: PDF Allaaambrinodes
Translation: 0x0416 0x04e4

Win32/TrojanDownloader.Delf_AGen.D also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38835308
FireEyeTrojan.GenericKD.38835308
McAfeeArtemis!E44CCB84DD22
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
BitDefenderThetaGen:NN.ZelphiF.34212.@V0@aqDqwhbk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf_AGen.D
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
BitDefenderTrojan.GenericKD.38835308
RisingDownloader.Delf_AGen!8.1311B (CLOUD)
Ad-AwareTrojan.GenericKD.38835308
EmsisoftTrojan.GenericKD.38835308 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
SophosMal/Generic-S (PUA)
IkarusTrojan.Win32.Krypt
GDataTrojan.GenericKD.38835308
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Mamson.A!ac
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38835308
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3585471238
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.FPAH!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/TrojanDownloader.Delf_AGen.D?

Win32/TrojanDownloader.Delf_AGen.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment