Backdoor

How to remove “Backdoor:Win32/Delf”?

Malware Removal

The Backdoor:Win32/Delf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Delf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Delf?


File Info:

crc32: DC7264BD
md5: d5f0c149b5c73e09fdb4b33ccc4eb26f
name: setup_spykeyspy.exe
sha1: e455b3fc6147e0d048981d3e146af43c9b12ecb6
sha256: 70100e45d07a8ba24f033f34811abacd29911a639a3f38ec3a8f8c0e56786b33
sha512: c2c8cff327d1ef6ec26c19166a23cff3485a72ba7ec032d608fef60106819df52b8d742af1506f7a23693a89ad13dfe8671d254e7adc8324b253a4be4d9d7d71
ssdeep: 12288:XQlmhLR6QXTFKFtCTXDmEcrOfR0WagtwaggxGq7WI78dlbZSePnWN:gk7YF8DmYRb9tfpGqyI4d/V8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) SoftArtStudio
FileDescription: SpyKeySpy Installation
FileVersion: 1.0
CompanyName: SoftArtStudio

Backdoor:Win32/Delf also known as:

DrWebBackDoor.Radoor
MicroWorld-eScanGen:Variant.Application.Graftor.60437
FireEyeGen:Variant.Application.Graftor.60437
Qihoo-360Win32/Virus.Spy.fd6
McAfeeArtemis!D5F0C149B5C7
CylanceUnsafe
VIPRESpyKeySpy
AegisLabRiskware.Win32.HideProc.1!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Application.Graftor.60437
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9b5c73
TrendMicroSpyware_KEYL_SpyKey
CyrenW32/Risk.LHSL-3687
AvastWin32:Trojan-gen
GDataTrojan.Spy.Keyspy.Q
Kasperskynot-a-virus:RiskTool.Win32.HideProc.nk
AlibabaRiskWare:Win32/HideProc.2a957156
NANO-AntivirusTrojan.Win32.Radoor.dfcgxn
SophosTroj/Radium-A
ComodoMalware@#2qjo4m1grb5wt
F-SecureDropper.DR/Delf.afe.1
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Application.Graftor.60437 (B)
IkarusTrojan.Win32.Rawdoor
F-ProtW32/Malware!8e66
WebrootHack.Tool.SpyKeySpy
AviraDR/Delf.afe.1
Antiy-AVLTrojan[Monitor]/Win32.ActualSpy
ArcabitTrojan.Spy.Keyspy.Q
ZoneAlarmnot-a-virus:RiskTool.Win32.HideProc.nk
MicrosoftBackdoor:Win32/Delf
MAXmalware (ai score=82)
PandaGeneric Malware
ESET-NOD32Win32/Rawdoor.A
TrendMicro-HouseCallSpyware_KEYL_SpyKey
TencentWin32.Trojan.Delf.Wtwy
FortinetRiskware/KeySpy
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Backdoor:Win32/Delf?

Backdoor:Win32/Delf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment