Malware

About “Delf.217” infection

Malware Removal

The Delf.217 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Delf.217 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Delf.217?


File Info:

crc32: DCFB6364
md5: 9c370e25e8c0f9321f4e9cb420d1fb6d
name: AutoUpdate.exe
sha1: 8bfc5abd5008efde85f20a37642dc349cb40c6ed
sha256: fe9a1f862104dc55dadde2b59710a66a9565ea9700c22476d1b02daf3055b2d2
sha512: 42e2c740c3c689e0b31bc4771b46793d1cafd69d26a00b1e04bae92d956f0c1a162159c795af7182e0c606ee392ab163945a161efd95e5efee45470f702690ed
ssdeep: 24576:jWS6IvSCm6CL3eX8vHPxkr6BuSj66mKGWdQEA4xjSitq6hDtL/LVnNqSyFT0e8+:+LhQSyKGSZpw61tLzVnNqS0THqT1O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.0.0
CompanyName: Wuxinji
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
Translation: 0x0804 0x03a8

Delf.217 also known as:

MicroWorld-eScanGen:Variant.Delf.217
CAT-QuickHealTrojan.Agent
McAfeeArtemis!9C370E25E8C0
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Delf.217
APEXMalicious
GDataGen:Variant.Delf.217
AlibabaTrojan:Win32/Tiggre.c8a5a3d3
AegisLabTrojan.Win32.Delf.4!c
RisingTrojan.Zpevdo!8.F912 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Delf.Agent.wffrz
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.9c370e25e8c0f932
EmsisoftGen:Variant.Delf.217 (B)
IkarusTrojan.Delf.Agent
CyrenW32/Trojan.BOGO-5547
MaxSecureTrojan.Malware.9862065.susgen
AviraTR/Delf.Agent.wffrz
WebrootW32.Malware.Gen
MAXmalware (ai score=89)
ArcabitTrojan.Delf.217
MicrosoftTrojan:Win32/Tiggre!rfn
Acronissuspicious
ALYacGen:Variant.Delf.217
Ad-AwareGen:Variant.Delf.217
YandexTrojan.Delf!e2GI7AejPJM
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
BitDefenderThetaGen:NN.ZelphiF.34106.PP0@a0WxEQpj
Cybereasonmalicious.5e8c0f

How to remove Delf.217?

Delf.217 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment