Malware

Troj/Delf-HFU malicious file

Malware Removal

The Troj/Delf-HFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Delf-HFU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Troj/Delf-HFU?


File Info:

crc32: BC5AFC1B
md5: 74891f540e3e635e8588ffce8018f0ec
name: brownbob.exe
sha1: 80786a7c9011d51831e21154cbb0890c4b3dfffd
sha256: 0945adb3a2371006386e9cf8812d2bdd36b4bea1d03cab4ed59155e0009e43a3
sha512: 2afd41205226d0f8f9a132c7f0b7d85994727c62dbc1d581f7fc27f4d715f1f5e5bbce102d525bf8bf5bc8206e26704affc3b0c0f7f131f235f3abd1abc8ea9d
ssdeep: 12288:C9l/HDJutqlC7tOj8GPhuDTyxPD7g7f5BzoDrtpg2MIe3pA58u9scUp:C/VukM7ioOtPg1tsrtpg2Je28Xp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Delf-HFU also known as:

MicroWorld-eScanTrojan.Agent.EISG
FireEyeGeneric.mg.74891f540e3e635e
ALYacSpyware.LokiBot
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.EISG
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c9011d
TrendMicroTSPY_HPLOKI.SMALY
BitDefenderThetaGen:NN.ZelphiF.32519.!GW@aGwe5ibi
CyrenW32/Injector.YKLI-9311
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.Agent.EISG
KasperskyHEUR:Backdoor.Win32.Androm.gen
AlibabaTrojan:Win32/Fareit.5d7fb6d9
NANO-AntivirusTrojan.Win32.Stealer.gkotjz
ViRobotTrojan.Win32.Z.Injector.1029632.AF
RisingTrojan.Wacatac!8.10C01 (TFE:5:gPWrsjK8dRH)
Ad-AwareTrojan.Agent.EISG
SophosTroj/Delf-HFU
ComodoMalware@#1pe5d85i4bcyq
DrWebTrojan.PWS.Stealer.19347
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.fh
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent (A)
IkarusTrojan.Inject
F-ProtW32/Injector.IPV
JiangminBackdoor.Androm.asao
Antiy-AVLTrojan[Backdoor]/Win32.Androm
Endgamemalicious (high confidence)
ArcabitTrojan.Agent.EISG
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Win-Trojan/Delphiless02.Exp
Acronissuspicious
McAfeeFareit-FQP!74891F540E3E
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
PandaTrj/Genetic.gen
ZonerTrojan.Win32.84527
ESET-NOD32a variant of Win32/Injector.EJJK
TrendMicro-HouseCallTSPY_HPLOKI.SMALY
FortinetW32/Injector.DZGI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Troj/Delf-HFU?

Troj/Delf-HFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment