Malware

About “Delf.21” infection

Malware Removal

The Delf.21 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Delf.21 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Delf.21?


File Info:

name: B928ADFD4591FAA6E3AE.mlw
path: /opt/CAPEv2/storage/binaries/706592228741d705153233d1dd5fe5e1b0c700bf17673887ed99f854be90a56a
crc32: 95F0CF84
md5: b928adfd4591faa6e3ae5ae3f2b86f20
sha1: 4b32ad2e5a832ad3c1078f4985e2ae0deaf5ced3
sha256: 706592228741d705153233d1dd5fe5e1b0c700bf17673887ed99f854be90a56a
sha512: 643c1617814443655f8af6d4c06a677ab981f613dcff4927a34e88ec67de4443430625bebc0b39f185cb8420d36a93aafab8db36a343047925f8aa7969068ae9
ssdeep: 12288:hr/ppkkACNSNy5FUpHrhkBdOyUrAyWx0f86J8U:hjnANy5IHNgisx0fa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2E47D22B2E14433D1631A399C1BA3799C3ABF106E29B9477BF91D4C4F796813C292D7
sha3_384: f7ee93ad88e86e0403bb439198d2d5e8c7caeaf6be49532c43b03e342fbc6abbfbdd8639aea5ea3643bfbabff32361d9
ep_bytes: 558bec83c4f0b874d04800e84c8ff7ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Delf.21 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.b928adfd4591faa6
SkyhighBehavesLike.Win32.ObfuscatedPoly.jh
McAfeeDownloader-CPS.a
Cylanceunsafe
VIPREGen:Variant.Delf.21
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Sadenav.628a071a
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_70% (W)
VirITTrojan.Win32.Generic.AINP
SymantecDownloader
ESET-NOD32a variant of Win32/Sadenav.AB
APEXMalicious
ClamAVWin.Downloader.Zard-9956821-0
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderGen:Variant.Delf.21
NANO-AntivirusTrojan.Win32.DownLoad2.ctfmk
MicroWorld-eScanGen:Variant.Delf.21
AvastWin32:Banload-GWU [Trj]
TencentMalware.Win32.Gencirc.13f432df
EmsisoftGen:Variant.Delf.21 (B)
F-SecureTrojan.TR/Adload.BX.172
DrWebTrojan.DownLoad2.19272
ZillyaDownloader.Adload.Win32.10382
TrendMicroTROJ_ADLOAD.SMIB
SophosMal/Overt-A
IkarusTrojan.Win32.Sadenav
JiangminTrojan/Generic.aezng
GoogleDetected
AviraTR/Adload.BX.172
Antiy-AVLTrojan[Downloader]/Win32.Adload
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#3jmry4nqovj0k
ArcabitTrojan.Delf.21
ZoneAlarmHEUR:Trojan-Downloader.Win32.Adload.gen
GDataGen:Variant.Delf.21
VaristW32/AdLoad.AP.gen!Eldorado
AhnLab-V3Win-Trojan/Overtls15.Gen
BitDefenderThetaGen:NN.ZelphiF.36744.OGW@aSm!1kaO
ALYacGen:Variant.Delf.21
MAXmalware (ai score=100)
VBA32BScope.Trojan.Download
MalwarebytesKraddare.Adware.Advertising.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_ADLOAD.SMIB
RisingTrojan.Win32.Fednu.fum (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1913668.susgen
FortinetW32/Overt.A!tr
AVGWin32:Banload-GWU [Trj]
Cybereasonmalicious.e5a832
DeepInstinctMALICIOUS

How to remove Delf.21?

Delf.21 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment