Malware

Delf.81 (B) (file analysis)

Malware Removal

The Delf.81 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Delf.81 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Delf.81 (B)?


File Info:

name: D84FB99C7B1114DD077E.mlw
path: /opt/CAPEv2/storage/binaries/a0b0aeab230845f1c9c7a5e25a0abd22e96c0c184273515da25a0aa44adb247d
crc32: 1076A848
md5: d84fb99c7b1114dd077edf9534c23570
sha1: cee4ec9ac7dc3bdc7b1f0d534541a32aa8b59689
sha256: a0b0aeab230845f1c9c7a5e25a0abd22e96c0c184273515da25a0aa44adb247d
sha512: 2339aa2af269215403af04994314dba938caff7104aa960ef0a9e0a477749cf91d98c37443dd7b965cf1ce79e52ba00f13bfa79b3f59d4c1a3930ccdde50d13e
ssdeep: 49152:jZM5E25xulcDWcUpf+TAjoeeaeGkdFDT:FM51OmWpoe9eGkdFDT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A8533E3D21496FDF0250036BC17B4201BB3A86628D65A73F72CB21A9377B115B6EF16
sha3_384: 823d00dacf0a5279852dfd0867ff12ae1926af6205083683f924699ec996926be3d74579274de87fc1b88f62ed300a60
ep_bytes: 60be00208e008dbe00f0b1ffc7871cbc
timestamp: 2016-03-17 12:46:14

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Delf.81 (B) also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Delf.81
FireEyeGen:Variant.Delf.81
ALYacGen:Variant.Delf.81
APEXMalicious
BitDefenderGen:Variant.Delf.81
EmsisoftGen:Variant.Delf.81 (B)
VIPREGen:Variant.Delf.81
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminemalicious.moderate.ml.score
GDataGen:Variant.Delf.81
MAXmalware (ai score=80)
ArcabitTrojan.Delf.81
McAfeeArtemis!D84FB99C7B11
VBA32TScope.Trojan.Delf
TrendMicro-HouseCallTROJ_GEN.R002H09H423
RisingTrojan.Generic@AI.94 (RDML:C5MKigrrDZFgqa2M9mARyA)
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.c7b111
DeepInstinctMALICIOUS

How to remove Delf.81 (B)?

Delf.81 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment