Backdoor

About “Backdoor.Delf.Spold.A” infection

Malware Removal

The Backdoor.Delf.Spold.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Delf.Spold.A virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor.Delf.Spold.A?


File Info:

name: 274710F5F6B43BD44876.mlw
path: /opt/CAPEv2/storage/binaries/cfd6bcd0fa9315f20c23f672fd5e33f33517ac9448cc0c2e16de0dbd394175e2
crc32: 71662B25
md5: 274710f5f6b43bd4487696ebd3b333fc
sha1: fa7913e1743d3ea81f42ee2e3090d1f5eca7fa65
sha256: cfd6bcd0fa9315f20c23f672fd5e33f33517ac9448cc0c2e16de0dbd394175e2
sha512: b09cef8cd85f4fd70dad8cc0e3a15cabe52307dbb56d72905e069fa3390c31e40d81e96bda3a65f48e433b92b61ead32818a6653618033afbf49b5dd65512f24
ssdeep: 6144:mw+5iVrYjQf/KOgzTrMzWdKT1f/5dWDquH2sJgHvKr8e0:ooVrZf/ATwzbS2mgPl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180840282FA87DE70C58149348A5ACF646F36FD25FDA402533688BB9F1CB71811E6A707
sha3_384: 57a684e143084809dff6e2cd4740634db83d81e4a17444b6d734402a4b56c649092ea8d63a582d2bb3fa1e1001a7653e
ep_bytes: f5b984420000e99d00000028f3946569
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Delf.Spold.A also known as:

BkavW32.OfficeOverQKA.Fam.Worm
tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Delf.Spold.A
FireEyeGeneric.mg.274710f5f6b43bd4
CAT-QuickHealW32.Virut.G
ALYacBackdoor.Delf.Spold.A
CylanceUnsafe
ZillyaVirus.Nakuru.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( f10002001 )
K7GWVirus ( f10002001 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Virus.Nakuru.a
VirITWin32.Scribble.A
CyrenW32/Virut.AI!Generic
SymantecBackdoor.Delf
Elasticmalicious (high confidence)
ESET-NOD32Win32/Virut.NBP
APEXMalicious
ClamAVWin.Trojan.Generic-42
KasperskyVirus.Win32.Nakuru.a
BitDefenderBackdoor.Delf.Spold.A
NANO-AntivirusTrojan.Win32.Hesv.itombk
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Virtu-A [Inf]
TencentVirus.Win32.Nakuru.a
Ad-AwareBackdoor.Delf.Spold.A
EmsisoftBackdoor.Delf.Spold.A (B)
ComodoTrojWare.Win32.TrojanDropper.Loops.A_10@1n8q4f
DrWebWin32.HLLP.Kespo
VIPREBackdoor.Delf.Spold.A
TrendMicroPE_VIRUX.A-1
McAfee-GW-EditionBehavesLike.Win32.BadFile.fc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Delf
GDataBackdoor.Delf.Spold.A
JiangminWin32/PatchFile.iw
AviraTR/Drop.Loops.A.1
MAXmalware (ai score=84)
ArcabitBackdoor.Delf.Spold.A
ViRobotWin32.Nakuru.A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C113396
McAfeeArtemis!274710F5F6B4
VBA32Virus.Virut.06
MalwarebytesMalware.AI.2088660215
TrendMicro-HouseCallPE_VIRUX.A-1
RisingMalware.UDM!0.18A076 (CLASSIC)
YandexTrojan.GenAsa!crAYjzJGleo
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Nakuru.A
FortinetW32/Virut.CE
BitDefenderThetaAI:FileInfector.C9457D4313
AVGWin32:Virtu-A [Inf]
Cybereasonmalicious.5f6b43

How to remove Backdoor.Delf.Spold.A?

Backdoor.Delf.Spold.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment