Malware

Delf.39 removal instruction

Malware Removal

The Delf.39 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Delf.39 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Delf.39?


File Info:

name: 66F80579BA9FF074760A.mlw
path: /opt/CAPEv2/storage/binaries/e912b57352533f837f3b650cb0cbbf931cce39597b6b1f3332f5ba7134b07a03
crc32: FA960230
md5: 66f80579ba9ff074760a40fa013cbe14
sha1: e03d50f6bbf0d0dfdd85e542f07dfb7f4cf96265
sha256: e912b57352533f837f3b650cb0cbbf931cce39597b6b1f3332f5ba7134b07a03
sha512: e3d889d7025ff139cdf3c15afccffe426434519070cb37b437990ac9287dc24857397c9f50f3f5a08b105687d51d5757620d497edd0a11d336380abd6050fb05
ssdeep: 24576:EXzKtfZNYeZHiitaBsSyqxwEluQG9mx9AK6vS2sTeko:vYmSAEJ9AVvaTe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3855B127284543BD0320B3B4C6BD6926C3B7A213E5D8E5B2FF44A4E5E396426C3EB57
sha3_384: 8a536f3a7f90db9ba5ec1b60ddb62387c2b771cfc15143ef977e58ba9b357ed8c51387b725486bec661cd1b77e9eb365
ep_bytes: 558bec83c4e8535633c08945ec8945e8
timestamp: 2011-05-31 10:17:46

Version Info:

0: [No Data]

Delf.39 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Delf.39
SkyhighBehavesLike.Win32.Infected.th
McAfeeArtemis!66F80579BA9F
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Delf.39
SangforTrojan.Win32.Save.a
AlibabaTrojanDownloader:Win32/Nirava.163940b0
K7GWTrojan-Downloader ( 002669f61 )
K7AntiVirusTrojan-Downloader ( 002669f61 )
VirITTrojan.Win32.Pher.IEE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.PVZ
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_004660.TOMB
Paloaltogeneric.ml
ClamAVWin.Trojan.Delf-2349
KasperskyTrojan-Downloader.Win32.Pher.iee
BitDefenderGen:Variant.Delf.39
NANO-AntivirusTrojan.Win32.Pher.bsjyyf
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b94ea9
EmsisoftGen:Variant.Delf.39 (B)
GoogleDetected
F-SecureTrojan.TR/Dldr.Nirava.93
DrWebTrojan.DownLoad2.46361
ZillyaDownloader.Pher.Win32.4731
TrendMicroTROJ_AGENT_004660.TOMB
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.66f80579ba9ff074
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Pher.avg
WebrootW32.Rogue.Gen
VaristW32/Nirava.B.gen!Eldorado
AviraTR/Dldr.Nirava.93
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Pher
KingsoftWin32.Troj.Undef.a
MicrosoftTrojanDownloader:Win32/Troxen!rts
XcitiumTrojWare.Win32.TrojanDownloader.Nirava.~stf@3r0sxi
ArcabitTrojan.Delf.39
ZoneAlarmTrojan-Downloader.Win32.Pher.iee
GDataGen:Variant.Delf.39
CynetMalicious (score: 99)
AhnLab-V3Downloader/Win32.Totoran.R5022
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Variant.Delf.39
TACHYONTrojan/W32.SxGuide.Gen
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDownloader.Pher!8.13C9 (TFE:5:XHKFgwiizGN)
YandexTrojan.GenAsa!AgLUnJdMyqA
IkarusTrojan-Downloader.Win32.Pher
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Pher.IEQ!tr.dldr
BitDefenderThetaGen:NN.ZelphiF.36804.PPW@am9LjbnO
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Delf.PVZ

How to remove Delf.39?

Delf.39 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment