Trojan

About “Win32/TrojanDropper.Delf.AAH” infection

Malware Removal

The Win32/TrojanDropper.Delf.AAH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Delf.AAH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Win32/TrojanDropper.Delf.AAH?


File Info:

name: 173A3D4AAD4ED56B1622.mlw
path: /opt/CAPEv2/storage/binaries/4d51edbfe2f0cdd915b41a5fe5acb6138e3f85d524d929699974f7f8fadadb5e
crc32: 622E54F2
md5: 173a3d4aad4ed56b1622aa9af55adae9
sha1: cf0f961694e50abc4c092198fc8c3d310d120d16
sha256: 4d51edbfe2f0cdd915b41a5fe5acb6138e3f85d524d929699974f7f8fadadb5e
sha512: 0aba089a0dfa9c6b1590d39914c53502c043b759ad689b00be64989bb1f3a56c8b366282fdb4fe874fa679cf84e62df96b9e69c82adac6a86e2d52e6ac8192f1
ssdeep: 12288:sdzX+wstet23OpFUy2E8B/NitB0ZUfrZnzzaXmSKw5BbvpwY7CJ/ZYTDzJ/ndPw6:sdzX+wstet23iFUy18B/NitB0ZUfrZno
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105E48D59BFB464AEC7658E3106F31AEB7B3B98122A50EBD7E1A767111D005F3CF22214
sha3_384: d61efede27ad6f800f11a9d70db1ff5643a25a0ef5ee3d5ed93251bbc39115b43f17b59017e15787c3f57b80e4cb4277
ep_bytes: 558bec83c4f05356b8ec3e4000e81af4
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/TrojanDropper.Delf.AAH also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.l566
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ProcessHijack.RGW@amGisGmi
FireEyeGeneric.mg.173a3d4aad4ed56b
CAT-QuickHealBackdoor.Hupigon.32817
SkyhighBehavesLike.Win32.Nofear.bh
ALYacGen:Trojan.ProcessHijack.RGW@amGisGmi
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Buzus.Win32.20970
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Trojan.ProcessHijack.RGW@amGisGmi
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.694e50
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Delf.AAH
APEXMalicious
ClamAVWin.Trojan.Buzus-4253
KasperskyTrojan.Win32.Buzus.afwx
AlibabaBackdoor:Win32/Buzus.6268f006
NANO-AntivirusTrojan.Win32.Buzus.yndv
ViRobotTrojan.Win32.Buzus.729600.B
RisingBackdoor.Win32.ShangXing.agf (CLASSIC)
EmsisoftGen:Trojan.ProcessHijack.RGW@amGisGmi (B)
F-SecureTrojan.TR/Hijacker.Gen
DrWebBackDoor.Beizhu.3103
VIPREGen:Trojan.ProcessHijack.RGW@amGisGmi
TrendMicroMal_Run-3
Trapminemalicious.high.ml.score
SophosMal/Dropper-G
IkarusTrojan-PWS.Win32.QQPass
MAXmalware (ai score=99)
GDataGen:Trojan.ProcessHijack.RGW@amGisGmi
JiangminTrojan/Buzus.fpm
GoogleDetected
AviraTR/Hijacker.Gen
VaristW32/FakeVideo.A.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.Hupigon
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Autorun.fi_2@1dw925
ArcabitTrojan.ProcessHijack.ED9F8C
ZoneAlarmTrojan.Win32.Buzus.afwx
MicrosoftBackdoor:Win32/Hupigon.CK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buzus.C40965
McAfeeW32/Autorun.worm.fi
DeepInstinctMALICIOUS
VBA32Trojan.Win32.Buzus.bf
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallMal_Run-3
YandexTrojan.GenAsa!kYlBz2ZA178
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.369742.susgen
FortinetW32/Injector.fam!tr
BitDefenderThetaAI:Packer.E8643AA11D
AVGWin32:Agent-ASP [Trj]
AvastWin32:Agent-ASP [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/TrojanDropper.Delf.AAH?

Win32/TrojanDropper.Delf.AAH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment