Malware

Troj/Delf-HOP removal guide

Malware Removal

The Troj/Delf-HOP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Delf-HOP virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Executes the printer spooler process
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Delf-HOP?


File Info:

name: F976527C91D9212C34B5.mlw
path: /opt/CAPEv2/storage/binaries/f863da39156fa8ffa1fa38342ae71117840fadd2b7bee80c42c7e6cc8b71a1d6
crc32: 5BF5D37B
md5: f976527c91d9212c34b56b7ea6b154bb
sha1: 9de3a08fa274e8e7757a4fab4c2ab9b31e09f89a
sha256: f863da39156fa8ffa1fa38342ae71117840fadd2b7bee80c42c7e6cc8b71a1d6
sha512: d47bb536ba9155b79cacaf8ea32791a92c1a012b3c4f95eff7daba61939fbba45a6f2496cd6e310ba983f20701379911d46450ec9d44a3501b3c4d96e50c2ff7
ssdeep: 24576:j9CPU2N9CnUDCRYFTUE4h/ETS4Cq3S7qdV0wbsYAG5tU+L4qEqHJ+QLxFxlC:wPU2NsngCRaTm/ETJVBAYAOtUJNAEQ3i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC6533E6F9146067ECDA0335074A187BAF86DEEB5D6DC7CA1B12B43ABD4B354910880F
sha3_384: 8a07fee7b50b96e982ac92a8f658b37a6f03c7f47b3de069d3cecde4e59f27b9914757ff05dd6e62760561edb180ffe7
ep_bytes: 60be009041008dbe0080feff5789e58d
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Troj/Delf-HOP also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.34338697
CAT-QuickHealTrojan.FsysnaIH.S15866952
ZillyaTrojan.Fsysna.Win32.63576
K7AntiVirusTrojan ( 005325821 )
K7GWTrojan ( 005325821 )
CyrenW32/Bancteian.KKKG-3314
ESET-NOD32Win32/Bancteian.D
APEXMalicious
ClamAVWin.Malware.Fsysna-7358359-0
KasperskyHEUR:Trojan.Win32.Fsysna.gen
BitDefenderTrojan.GenericKD.34338697
NANO-AntivirusTrojan.Win32.Bancteian.henbyq
AvastWin32:TrojanX-gen [Trj]
EmsisoftTrojan.GenericKD.34338697 (B)
DrWebTrojan.MulDrop8.57276
VIPRETrojan.GenericKD.34338697
McAfee-GW-EditionGenericR-OCV!7F78DBB933E1
FireEyeTrojan.GenericKD.34338697
SophosTroj/Delf-HOP
IkarusTrojan.Agent
JiangminTrojan.Fsysna.isy
GoogleDetected
Antiy-AVLTrojan/Win32.Fsysna
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Generic.D20BF789
ZoneAlarmHEUR:Trojan.Win32.Fsysna.gen
GDataTrojan.GenericKD.34338697
VBA32TScope.Trojan.Delf
ALYacTrojan.GenericKD.34338697
MAXmalware (ai score=82)
Cylanceunsafe
RisingStealer.Delf!8.415 (TFE:4:45p18v5R0NU)
FortinetW32/Bancteian.D!tr
BitDefenderThetaGen:NN.ZelphiF.36662.@V3@aaKrShci
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Troj/Delf-HOP?

Troj/Delf-HOP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment