Trojan

Trojan:Win32/DelfInject.RVR!MTB malicious file

Malware Removal

The Trojan:Win32/DelfInject.RVR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/DelfInject.RVR!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/DelfInject.RVR!MTB?


File Info:

crc32: 8400DD08
md5: d243052a864f576aee18da1a504d28c5
name: D243052A864F576AEE18DA1A504D28C5.mlw
sha1: 4f5e2695d6f056eff962213f6e918632195e8a9d
sha256: 5af151486027d69aa05149784773298808ef5ba77a114db79462afba4bc69873
sha512: 13b32c2bbaac3b4dfa5a765927f8d3c6bfdd40302339492185892e02efdc422153e3b83467c0830ef798648a4a3fcab5ad7ba17bba8a32ddc2689c7c8de74da0
ssdeep: 12288:MokUWg5OFBhsZUccZk8ME1rbCYxWecXgiQfNu5kLvRJx7:MGWdB0UcceiKYFcQiQFCkLJD7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/DelfInject.RVR!MTB also known as:

LionicTrojan.Win32.Remcos.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.7024
CAT-QuickHealBackdoor.Remcos
ALYacTrojan.GenericKD.37545022
CylanceUnsafe
ZillyaBackdoor.Remcos.Win32.4735
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Remcos.e2e13bc3
K7GWTrojan ( 00581d631 )
K7AntiVirusTrojan ( 00581d631 )
CyrenW32/Delf.OSCT-6350
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EQAL
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.37545022
NANO-AntivirusTrojan.Win32.Remcos.japjhv
MicroWorld-eScanTrojan.GenericKD.37545022
TencentMalware.Win32.Gencirc.10ceff71
Ad-AwareTrojan.GenericKD.37545022
SophosGeneric ML PUA (PUA)
ComodoMalware@#1prfxxp3naepc
TrendMicroTROJ_FRS.0NA103IE21
McAfee-GW-EditionFareit-FDBI!D243052A864F
FireEyeGeneric.mg.d243052a864f576a
EmsisoftMalCert-S.LO (A)
JiangminBackdoor.Remcos.dcz
WebrootW32.Trojan.Gen
AviraTR/Injector.thkto
Antiy-AVLTrojan/Generic.ASMalwS.348EC96
MicrosoftTrojan:Win32/DelfInject.RVR!MTB
GridinsoftTrojan.Win32.Downloader.oa!s1
ArcabitTrojan.Generic.D23CE43E
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataWin32.Trojan.Agent.9WD7Y1
AhnLab-V3Trojan/Win.Remcos.R440117
McAfeeFareit-FDBI!D243052A864F
MAXmalware (ai score=80)
VBA32Malware-Cryptor.Limpopo
MalwarebytesBackdoor.Remcos
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103IE21
RisingTrojan.Generic@ML.94 (RDML:MNQ7BkxGzDdOvxBhd1KOnw)
YandexTrojan.Injector!uj9h30nTvtY
IkarusTrojan.Inject
FortinetW32/Injector.EPZM!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/DelfInject.RVR!MTB?

Trojan:Win32/DelfInject.RVR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment