Malware

PWS:Win32/Delf.CR!bit (file analysis)

Malware Removal

The PWS:Win32/Delf.CR!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Delf.CR!bit virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Collects information about installed applications
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
qers.xyz

How to determine PWS:Win32/Delf.CR!bit?


File Info:

crc32: 9F0F0779
md5: 59136319b0e0a1184b7a6a4a77fed59e
name: 59136319B0E0A1184B7A6A4A77FED59E.mlw
sha1: 5fd23a1b9c2f3d61f9673e920d27896f47813531
sha256: 4531646d41d5956d52ff20eb74e9a238cc11a478501fb775323338c9c70fa1aa
sha512: 40adbb9afd76500bd43daa3ecf36111666b4339187f1477d79a81cccc7268668c0c01fbce83b3345a87ace616fa60df67bc1d95ddec5c830fb77a0fea1ed4ce4
ssdeep: 12288:i9ioOlNwYkbJaRgSfnkol1WrEO5biOOI+wHsaQvvm26fKgh:icoOlNRgSfnWr9celQvvm265h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Delf.CR!bit also known as:

LionicTrojan.Win32.Informer.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23656
ClamAVWin.Malware.Datastealer-6876938-0
ALYacGeneric.DataStealer.1.EFFB37A6
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanPSW:Win32/Informer.3b66c0f6
K7GWPassword-Stealer ( 004f4fb51 )
K7AntiVirusPassword-Stealer ( 004f4fb51 )
CyrenW32/Trojan.IVBQ-1365
SymantecInfostealer.Rultazo
ESET-NOD32Win32/PSW.Delf.OQK
ZonerTrojan.Win32.72584
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Informer.i
BitDefenderGeneric.DataStealer.1.EFFB37A6
NANO-AntivirusTrojan.Win32.MlwGen.egcbrk
MicroWorld-eScanGeneric.DataStealer.1.EFFB37A6
TencentMalware.Win32.Gencirc.10b8006b
Ad-AwareGeneric.DataStealer.1.EFFB37A6
SophosMal/Generic-S
ComodoTrojWare.Win32.Downloader.Homa.A@1nbe7m
BitDefenderThetaAI:Packer.A759A5FB21
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_SKEEYAH_GA250A04.UVPM
McAfee-GW-EditionBehavesLike.Win32.DealPly.hh
FireEyeGeneric.mg.59136319b0e0a118
EmsisoftGeneric.DataStealer.1.EFFB37A6 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.gpoqf
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1B66831
KingsoftWin32.Troj.Informer.i.(kcloud)
MicrosoftPWS:Win32/Delf.CR!bit
ArcabitGeneric.DataStealer.1.EFFB37A6
GDataGeneric.DataStealer.1.EFFB37A6
AhnLab-V3Malware/Win32.Generic.C1554628
McAfeeGenericR-IES!59136319B0E0
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Fareit
MalwarebytesSpyware.AzorUlt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_SKEEYAH_GA250A04.UVPM
RisingTrojan.Generic@ML.100 (RDML:RN6pupvlyNCiXoWXeKj/wA)
YandexTrojan.GenAsa!M57H7qmwv/Y
IkarusTrojan-PSW.Delf
FortinetW32/Generic.AC.36AED3!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PWS:Win32/Delf.CR!bit?

PWS:Win32/Delf.CR!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment