Trojan

Trojan.Agent.Delf.RVB information

Malware Removal

The Trojan.Agent.Delf.RVB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.Delf.RVB virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Accessed credential storage registry keys
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Touches a file containing cookies, possibly for information gathering
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.Delf.RVB?


File Info:

name: 11DEBF5B7A40746A1EC1.mlw
path: /opt/CAPEv2/storage/binaries/241ec17bed2d0d5f2ff988bacf0863da565862dfc3f5c57d37a786f90f7352da
crc32: C2542CE3
md5: 11debf5b7a40746a1ec1ca0a34e6db07
sha1: 8fab99b9ee0bb4f887a6fc140233310a2b3f7e80
sha256: 241ec17bed2d0d5f2ff988bacf0863da565862dfc3f5c57d37a786f90f7352da
sha512: 30ab773a1ce2157a74808141711551f158f3493f4557a630b334f308ebc575bf850a516e51113f01400196a0b483c310c268579d76cc0d0f9b6b0b502f93284b
ssdeep: 24576:awAcu99lPzvxP+Bsz2XjWTRMQckkIbOn0QZh9u:FAcIzpP+hickkIV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9155C32F6809937C92239F59C5A81D554257E202E28B9477AF63F0C6E791C3FE261CE
sha3_384: 94d4752375d8a10c9c33fb0d10923146ffb10eff1495435fe1b3f82eed8a3400d0d022f83e067c0ad6fe16830ed88f52
ep_bytes: 558becb92b0000006a006a004975f953
timestamp: 2011-02-18 11:13:48

Version Info:

0: [No Data]

Trojan.Agent.Delf.RVB also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Fasong.l4hb
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.Delf.RVB
FireEyeGeneric.mg.11debf5b7a40746a
SkyhighBehavesLike.Win32.Dropper.dm
McAfeeBackDoor-EZG.d
Cylanceunsafe
ZillyaTrojan.Delf.Win32.28296
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaBackdoor:Win32/Siscos.4f7965ae
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.b7a407
BitDefenderThetaAI:Packer.A1C6992921
SymantecSMG.Heur!gen
ESET-NOD32Win32/Delf.NVC
APEXMalicious
TrendMicro-HouseCallBKDR_FYNLOS.SMIA
ClamAVWin.Packed.Darkkomet-9819952-0
KasperskyTrojan.Win32.Siscos.bph
BitDefenderTrojan.Agent.Delf.RVB
NANO-AntivirusTrojan.Win32.TrjGen.dcmyd
SUPERAntiSpywareHeur.Agent/Gen-FakeChrome
AvastWin32:Delf-AIC [Trj]
TencentBackdoor.Win32.DarkKomet.artra
EmsisoftTrojan.Agent.Delf.RVB (B)
BaiduWin32.Backdoor.Agent.l
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.Siggen2.22967
VIPRETrojan.Agent.Delf.RVB
TrendMicroBKDR_FYNLOS.SMIA
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.CDur
GDataWin32.Trojan.PSE.1Y6NT5X
JiangminTrojan/Siscos.nm
WebrootW32.Siscos
GoogleDetected
AviraBDS/Backdoor.Gen
VaristW32/Banload.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Siscos
KingsoftWin32.Trojan.Siscos.bph
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Agent.Delf.RVB
ZoneAlarmTrojan.Win32.Siscos.bph
MicrosoftBackdoor:Win32/Fynloski.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R2290
VBA32Backdoor.DarkKomet.gen
ALYacTrojan.Agent.Delf.RVB
MAXmalware (ai score=100)
MalwarebytesGeneric.Trojan.Delf.DDS
PandaGeneric Malware
RisingBackdoor.DarkComet!1.CB87 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.DarkComet
FortinetW32/COMDAR.SMI!tr
AVGWin32:Delf-AIC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[dropper]:Win/Delf.NVC

How to remove Trojan.Agent.Delf.RVB?

Trojan.Agent.Delf.RVB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment