Malware

Should I remove “Troj/Delp-FL”?

Malware Removal

The Troj/Delp-FL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Delp-FL virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Delp-FL?


File Info:

crc32: EEB808AB
md5: 37537bd4c789ae212571172e5329006f
name: upload_file
sha1: 6ea602600c5acd3b9d0936988758e7f249d937ea
sha256: 525d7cd6b8b1fbb2dd7a3677290da462ad1457e481568729e3c60e7361c1f602
sha512: 33c4e6f7fed079ddc512ab9b80763c099be086eb0d1ede22a00bda1036bf732dd28970c2b43bcd88a5396dff2f046a5ff84229cd10373d7ef69d97512852cc09
ssdeep: 24576:mSIP/NfZxY1KNSw0RG/XPTsKs+3WkT2uPOeWeBCEE4nkfP6upq+a7Qm:mSo178rGvLsjREE8C6f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Troj/Delp-FL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71155
FireEyeGeneric.mg.37537bd4c789ae21
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKDZ.71155
MalwarebytesTrojan.MalPack.DLF
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005722b71 )
BitDefenderTrojan.GenericKDZ.71155
K7GWTrojan ( 005722b71 )
TrendMicroTrojan.Win32.WACATAC.USMANK320
CyrenW32/Injector.DUSE-5887
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9786580-0
KasperskyHEUR:HackTool.Win32.Agent.gen
AlibabaTrojanDownloader:Win32/Fareit.e7659324
Ad-AwareTrojan.GenericKDZ.71155
EmsisoftTrojan.GenericKDZ.71155 (B)
F-SecureTrojan.TR/Dldr.Delf.nflat
DrWebTrojan.Siggen10.44999
InvinceaMal/Generic-R + Troj/Delp-FL
McAfee-GW-EditionFareit-FZO!37537BD4C789
SophosTroj/Delp-FL
JiangminHackTool.Agent.dpi
AviraTR/Dldr.Delf.nflat
Antiy-AVLTrojan[Downloader]/Win32.Delf
MicrosoftPWS:Win32/Fareit.SM!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D115F3
ZoneAlarmHEUR:HackTool.Win32.Agent.gen
GDataTrojan.GenericKDZ.71155
CynetMalicious (score: 85)
AhnLab-V3Downloader/Win32.Agent.R349910
McAfeeFareit-FZO!37537BD4C789
MAXmalware (ai score=82)
ZonerTrojan.Win32.97011
ESET-NOD32Win32/TrojanDownloader.Delf.DBO
TrendMicro-HouseCallTrojan.Win32.WACATAC.USMANK320
RisingDownloader.Delf!8.16F (TFE:4:KQGazsqsCTH)
eGambitPE.Heur.InvalidSig
FortinetW32/Injector.EFPU!tr
BitDefenderThetaGen:NN.ZelphiCO.34590.qH2@a0J75ydk
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Troj/Delp-FL?

Troj/Delp-FL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment