Trojan

TrojanDropper:Win32/Delf.W removal guide

Malware Removal

The TrojanDropper:Win32/Delf.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Delf.W virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/Delf.W?


File Info:

name: 2D08AEB89D751F60FAA1.mlw
path: /opt/CAPEv2/storage/binaries/b0045d07e93a0073a9cb6465d58c7de6befc7ffa35a128e14a4d049d8600e62d
crc32: 742BB21E
md5: 2d08aeb89d751f60faa188e08da876c4
sha1: 099e892a34265444a2813ff09974b5a9b26af199
sha256: b0045d07e93a0073a9cb6465d58c7de6befc7ffa35a128e14a4d049d8600e62d
sha512: 3c64a60d5f328bf498497563189c29fc5cd5069c06967f241642a9a6bca872510f93ba7fab67791ee6f6c376973bb345b76bdc7270a536a84a414b6db362571a
ssdeep: 1536:l/qzLwkYhJqyfjH4tPvOKMADe4QV0tNIc/tBxug0RY5xDkAoRAU8:lSzkrhJqajH4tPvnZQVbc/tTu1O5OACy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA93CF8F750534F6E5333C32A4C3834AAA35FD77B43C3019FF4965CBA9A518239A9A21
sha3_384: 4d3b88bbb9b63a38e823341278bfb3a3e796bebc82f677e8ac76c3415e3c5ab63368e01c9e82ab790633138cb801890d
ep_bytes: 558bec83c4f0b8c8310020e8b4eaffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanDropper:Win32/Delf.W also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Crypt.BH
FireEyeGeneric.mg.2d08aeb89d751f60
CAT-QuickHealTrojan.Delfinject.17618
McAfeeBackDoor-CEP.w
MalwarebytesMachineLearning/Anomalous.100%
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3df1 )
BitDefenderTrojan.Crypt.BH
K7GWTrojan ( 0055e3df1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Backdoor.WPAG-0419
SymantecTrojan.Packed.5
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Delf.NCD
TrendMicro-HouseCallBKDR_DELF.BSG
ClamAVWin.Trojan.Delf-687
KasperskyPacked.Win32.CPEX-based.t
NANO-AntivirusTrojan.Win32.CPEXbased.wsxv
ViRobotBackdoor.Win32.Delf.343552
RisingBackdoor.Delf.vwk (CLASSIC)
SophosMal/Behav-328
F-SecureBackdoor.BDS/Delf.atg
DrWebBackDoor.Bifrost.998
VIPRETrojan.Crypt.BH
TrendMicroBKDR_DELF.BSG
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
Trapminemalicious.high.ml.score
CMCGeneric.Win32.2d08aeb89d!CMCRadar
EmsisoftTrojan.Crypt.BH (B)
IkarusTrojan.Win32.Buzus
GDataTrojan.Crypt.BH
JiangminBackdoor/Delf.arf
GoogleDetected
AviraBDS/Delf.atg
Antiy-AVLTrojan[Packed]/Win32.CPEX-based.t
XcitiumTrojWare.Win32.TrojanDropper.Delf.~F@hp7m
ArcabitTrojan.Crypt.BH
ZoneAlarmPacked.Win32.CPEX-based.t
MicrosoftTrojanDropper:Win32/Delf.W
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C14830
BitDefenderThetaAI:Packer.A197FDBA1E
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.Win32.Cigicigi
Cylanceunsafe
PandaGeneric Malware
APEXMalicious
TencentMalware.Win32.Gencirc.10b0d7cf
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/DELFINJECT.A!tr
AVGWin32:Delf-AUS [Trj]
Cybereasonmalicious.89d751
AvastWin32:Delf-AUS [Trj]

How to remove TrojanDropper:Win32/Delf.W?

TrojanDropper:Win32/Delf.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment