Trojan

Trojan.Win32.Delf.ndf removal instruction

Malware Removal

The Trojan.Win32.Delf.ndf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Delf.ndf virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Delf.ndf?


File Info:

name: 290F792BE33C56A756C6.mlw
path: /opt/CAPEv2/storage/binaries/025cca38ef1f0988814a5c9d8722cb7df4631d271dc5068722e2726a89007235
crc32: 6427ED0A
md5: 290f792be33c56a756c633ff92d76758
sha1: c773be0fc37aa3a57987e022ecd036eac33d26b2
sha256: 025cca38ef1f0988814a5c9d8722cb7df4631d271dc5068722e2726a89007235
sha512: b25371e964f358472f66b8fffe3650e7394ea378fecc8fd5c19c06c3201c384e9675fe3951bcc6fef6da8e3fb7684d87370e03fc734e2acfb5df132fceeebdfb
ssdeep: 24576:57lmFLkrUc//ebOCe4AUVOpzJPvXOUu8aJr:5BqNCFz5WUPaJr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C65B027B2A1143FC16356348C7B87A9693ABF002E28988B3BF51E4C6F3574179E7197
sha3_384: c2cd23422e3fa8bd0f83e91b1e7088188ed62619d252b3b376a56dacceb9649524694a3a65c5a4f28f23df86b00458e3
ep_bytes: 558bec83c4f0b8743a4c00e86c2cf4ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: TENEW
FileDescription:
FileVersion: 0.3.2.9
InternalName:
LegalCopyright: 玉萧居士
LegalTrademarks:
OriginalFilename: 系统通用利用程序V 5.0
ProductName:
ProductVersion: V 5.0
Comments:
Translation: 0x0804 0x03a8

Trojan.Win32.Delf.ndf also known as:

DrWebTrojan.Siggen4.7437
CylanceUnsafe
SangforTrojan.Win32.Delf.buxin
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/MalwareF.b1fa2137
K7GWTrojan ( 7000000f1 )
VirITTrojan.Win32.Generic.ASBX
CyrenW32/Risk.OKLI-9089
SymantecBackdoor.Graybird
KasperskyTrojan.Win32.Delf.ndf
NANO-AntivirusTrojan.Win32.Hupigon.dgwegt
AvastWin32:Malware-gen
RisingTrojan.FileLock.a (CLOUD)
ComodoMalware@#12qxo248g5q34
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
IkarusBackdoor.Win32.Hupigon
JiangminTrojan/Delf.kfj
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.343BC0
KingsoftWin32.Troj.FileLock.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGeneric.bot
APEXMalicious
TencentMalware.Win32.Gencirc.1139d30e
YandexTrojan.GenAsa!gbCSm9GZ8es
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Hupigon.MGVDYPV
AVGWin32:Malware-gen
PandaGeneric Malware

How to remove Trojan.Win32.Delf.ndf?

Trojan.Win32.Delf.ndf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment