Trojan

Trojan:Win32/Delflob.I removal

Malware Removal

The Trojan:Win32/Delflob.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Delflob.I virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Unconventionial language used in binary resources: Ukrainian
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Delflob.I?


File Info:

name: 76694FB9B5F5BCFF77B6.mlw
path: /opt/CAPEv2/storage/binaries/f73abbce53cf52c24ef7293b88af21a4003f89b9dc3046f5a871f0adbd27106e
crc32: 560377AD
md5: 76694fb9b5f5bcff77b63ee11749d30f
sha1: c92e8a9819b96904ca245c4a9e55d26f7a196f90
sha256: f73abbce53cf52c24ef7293b88af21a4003f89b9dc3046f5a871f0adbd27106e
sha512: 88105e7dbacfb831b2fa44bb7647c0fea8c978ec68d307f6f34209cbbd1263d2c5dd654473db9462683131e931e2a63fe0b4f966262729eabd196854fcabb2b3
ssdeep: 3072:9dC5xrEhUhLnFrW1eZrZf8on5AVMN9R7/Nz1vAXvZ1Tc5bwm:9d64hkBrW4IuNN9R755k6L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A00412B3BD5A956DD847C43180E3CB02823DE5716EE0CB07B8299C29FCDF0615C9AEA5
sha3_384: 2978c833b1733689689ff1da36bb98be83cfab4cdba7b6c807ba441f54fba9075d9ebd9e0a42c9fd851f4b4bc4733cf0
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Delflob.I also known as:

LionicTrojan.Win32.Delf.4!c
DrWebTrojan.MulDrop.12726
MicroWorld-eScanAdware.Generic.3023295
McAfeeArtemis!76694FB9B5F5
CylanceUnsafe
K7AntiVirusAdware ( 004bebcd1 )
AlibabaTrojan:Win32/Delflob.aa369f8f
K7GWAdware ( 004bebcd1 )
BitDefenderThetaAI:Packer.F27412C119
CyrenW32/Delf.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.IeDefender.AA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zlob-4412
BitDefenderAdware.Generic.3023295
AvastWin32:Delf-IWG [Trj]
Ad-AwareAdware.Generic.3023295
EmsisoftAdware.Generic.3023295 (B)
TrendMicroTROJ_GEN.R002C0DLA21
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.76694fb9b5f5bcff
SophosMal/Generic-S (PUA)
SentinelOneStatic AI – Malicious PE
GDataAdware.Generic.3023295
JiangminTrojanDownloader.Delf.ieq
eGambitUnsafe.AI_Score_99%
AviraADWARE/IEDefender.kbbwg
Antiy-AVLTrojan/Generic.ASMalwS.34E59CB
GridinsoftRansom.Win32.Sabsik.sa
ArcabitAdware.Generic.D2E21BF
MicrosoftTrojan:Win32/Delflob.I
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C35030
VBA32TScope.Trojan.Delf
ALYacAdware.Generic.3023295
MAXmalware (ai score=65)
MalwarebytesAdware.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0DLA21
RisingTrojan.Win32.Delf.yjs (CLASSIC)
YandexTrojan.DL.Delf!nD++EcS6G/w
IkarusTrojan-Downloader.Win32.Peregar
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/IeDefender
AVGWin32:Delf-IWG [Trj]
Cybereasonmalicious.819b96
PandaTrj/CI.A

How to remove Trojan:Win32/Delflob.I?

Trojan:Win32/Delflob.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment