Malware

Delf.179 malicious file

Malware Removal

The Delf.179 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Delf.179 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Delf.179?


File Info:

name: 6B380C0BAA7C863D3CE6.mlw
path: /opt/CAPEv2/storage/binaries/12d27670f0e3b51d6c13fc5f9695eb608d9d5a24497a6b5478df8a44e30c4a02
crc32: 712FE780
md5: 6b380c0baa7c863d3ce6f93dc32f273f
sha1: 2e891a9fc9f4ca5b7c8b6f99205805947f23e38a
sha256: 12d27670f0e3b51d6c13fc5f9695eb608d9d5a24497a6b5478df8a44e30c4a02
sha512: 1b96156609eaaa893cecfa56b5d6d9bc5dd19c31758592136c13e6f25d7551279f51d4d53f3d5243264cd0b44d43f88a800649986aadbbc6b85a755c43b71844
ssdeep: 1536:03rq8E0QSda9HQw4g3zmlm1wNub1rpAwvH943Y7iQM2igL0zxNKYSsI:0u0jOwK3z6m2NuZpACd43Y7iQMZgAxNg
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FB935A13B1C28872E7B11A789C16B358D4BBBE603D3F165B76E41D4E4D7C2D0A86C687
sha3_384: 9a553e7d924c8ac3e979508356084d7a079a9a5916ace6458e57f1b7bcef6e78f0fc2a7791cd94a56a11d6cc0f4b114f
ep_bytes: 558bec83c4c4535657b8cc2c4100e8a5
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Delf.179 also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Delf.179
FireEyeGen:Variant.Delf.179
CAT-QuickHealTrojan.BankerPMF.S19753244
SkyhighPWS-FCJC!6B380C0BAA7C
ALYacGen:Variant.Delf.179
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Banker.Win32.114544
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Banker.ea755bc5
K7GWSpyware ( 000ad77c1 )
K7AntiVirusSpyware ( 000ad77c1 )
ArcabitTrojan.Delf.179
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Banker.ADXG
APEXMalicious
ClamAVWin.Malware.Delf-9857498-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Delf.179
NANO-AntivirusTrojan.Win32.Banker1.eravoa
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10b1f3c5
EmsisoftGen:Variant.Delf.179 (B)
F-SecureHeuristic.HEUR/AGEN.1328476
DrWebTrojan.PWS.Banker1.22800
VIPREGen:Variant.Delf.179
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
GoogleDetected
AviraHEUR/AGEN.1328476
VaristW32/Banker.FO.gen!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.745
XcitiumTrojWare.Win32.Delf.TQW@76p66c
MicrosoftTrojanSpy:Win32/Banker
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Delf.179
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C1963173
McAfeePWS-FCJC!6B380C0BAA7C
MAXmalware (ai score=87)
VBA32TrojanSpy.Banker
Cylanceunsafe
PandaTrj/GdSda.A
RisingSpyware.Banker!1.ABA2 (CLASSIC)
YandexTrojan.GenAsa!AcXjAQlTgyg
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banker.ADXG!tr
AVGWin32:BankerX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Delf.179?

Delf.179 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment