Trojan

MemScan:Trojan.PWS.Delf.INS malicious file

Malware Removal

The MemScan:Trojan.PWS.Delf.INS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.PWS.Delf.INS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 3.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

duglazo.info

How to determine MemScan:Trojan.PWS.Delf.INS?


File Info:

crc32: 2FC122AD
md5: 173f86e01ac24f62a609382cd0789876
name: 3.exe
sha1: 432950d3edeee04f5ee16cfd876d97ac67012e25
sha256: 252399168184867c61d57702943c93d1b6870f6c820b5f442672cca9394eb6eb
sha512: 58ff367d60e7a412ec1335d8851818b4c2de2e22640bc481be6683955b1c55be740a5b0cad812d5330d2943e41a9aa4f647e2bc0233233a51655bc400eeea89b
ssdeep: 49152:urJJ2rMKHLNKXYuK3RAUjJbQnKGuRx01u:urerv4ouILFbQnOR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MemScan:Trojan.PWS.Delf.INS also known as:

DrWebTrojan.Siggen9.11657
MicroWorld-eScanTrojan.GenericKD.42587023
FireEyeGeneric.mg.173f86e01ac24f62
Qihoo-360Generic/HEUR/QVM19.1.3D5D.Malware.Gen
ALYacMemScan:Trojan.PWS.Delf.INS
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0040f4ef1 )
BitDefenderTrojan.GenericKD.42587023
K7GWTrojan ( 0040f4ef1 )
Cybereasonmalicious.01ac24
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34090.PzWaaWPV2qj
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42587023
KasperskyHEUR:Trojan.Win32.Generic
AlibabaPacked:Win32/Themida.d811ca8a
NANO-AntivirusTrojan.Win32.TPM.haphpv
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareTrojan.GenericKD.42587023
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.TPM.Gen
VIPREBackdoor.Win32.Ircbot.gen (v)
TrendMicroTROJ_FRS.VSNTBE20
McAfee-GW-EditionBehavesLike.Win32.Miuref.tc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42587023 (B)
IkarusTrojan.Win32.Themida
JiangminTrojan.Generic.eljak
AviraTR/Crypt.TPM.Gen
MAXmalware (ai score=81)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D289D38F
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Banload.AAA!bit
Acronissuspicious
McAfeeArtemis!173F86E01AC2
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.Themida.GZV
TrendMicro-HouseCallTROJ_FRS.VSNTBE20
TencentWin32.Trojan.Agent.Dwtr
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MemScan:Trojan.PWS.Delf.INS?

MemScan:Trojan.PWS.Delf.INS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment