Malware

What is “Troj/Delf-GBD”?

Malware Removal

The Troj/Delf-GBD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Delf-GBD virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the TWarBot malware family

How to determine Troj/Delf-GBD?


File Info:

name: AA0B8F288585A2311DF2.mlw
path: /opt/CAPEv2/storage/binaries/9ee46e4ec06c3cdcab54ce839779e96ff73fde5166ca7da615406239b5bef84b
crc32: 599A3A3C
md5: aa0b8f288585a2311df2cb25c89a451d
sha1: cd5dca85a08afd97ac2531bbd8a2f21be8390bc3
sha256: 9ee46e4ec06c3cdcab54ce839779e96ff73fde5166ca7da615406239b5bef84b
sha512: 9ed2cf0848130c91a97d1b19e2ee82cc1d6f875af864c5baae6e01d2aa08dd5dae5611dddbb702671f9e56f23ac3f79a04277fc4d23b21fb7fe4d98a4b39d92e
ssdeep: 6144:t731bdBaje4ZlXONWO6mZacjhoYQNqPIFejcl80dICyBt6JwZGWfflZBeI1RhCi9:91bfulxcjhoNNgPd0d764oGmfLBtJCXM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E74021FA940FEBAC96044BD8D1782BD6CA93F70DE5DD82EBEEC5A0D17A0386513C512
sha3_384: 0e409dff23c8ac8e0c213e02d6975c02cfbec0a1479a0e05684a2afd5c547300f15b01eea380247e64651640ce268f46
ep_bytes: e9926a0000c700010000000f9ac288d6
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Troj/Delf-GBD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Wabot.lh0Z
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DQQD
ClamAVWin.Trojan.Wabot-7053120-0
CAT-QuickHealBackdoor.Wabot.S17514
McAfeeBackDoor-FDOW!AA0B8F288585
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Delf.Win32.2229
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00517d761 )
AlibabaBackdoor:Win32/Wabot.462
K7GWTrojan ( 00517d761 )
Cybereasonmalicious.88585a
BaiduWin32.Backdoor.Wabot.a
VirITWin32.Wabot.A
CyrenW32/Wabot.N.gen!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Agent.DQQD
SUPERAntiSpywareBackdoor.Wabot
AvastWin32:Delf-VKC [Trj]
TencentTrojan.Win32.Wabot.a
SophosTroj/Delf-GBD
DrWebTrojan.MulDrop6.64369
VIPRETrojan.Agent.DQQD
TrendMicroBackdoor.Win32.WABOT.SMD
McAfee-GW-EditionBehavesLike.Win32.Wabot.fc
FireEyeTrojan.Agent.DQQD
EmsisoftTrojan.Agent.DQQD (B)
IkarusTrojan.Win32.Delf
GDataWin32.Backdoor.Wabot.A
JiangminBackdoor/Wabot.z
MAXmalware (ai score=81)
Antiy-AVLTrojan[Backdoor]/Win32.Wabot.a
XcitiumBackdoor.Win32.Poison.HYB@3nwaj4
ArcabitTrojan.Agent.DQQD
ViRobotBackdoor.Win32.Wabot.157619
MicrosoftBackdoor:Win32/Wabot!rfn
GoogleDetected
AhnLab-V3Backdoor/Win32.Wabot.R191213
Acronissuspicious
ALYacTrojan.Agent.DQQD
TACHYONBackdoor/W32.Wabot.345088
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
RisingWorm.Chilly!1.661C (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.W32.Wabot.A
FortinetW32/Agent.DQQD!tr
AVGWin32:Delf-VKC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Delf-GBD?

Troj/Delf-GBD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment