Trojan

VHO:Trojan.Win32.Delf removal guide

Malware Removal

The VHO:Trojan.Win32.Delf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan.Win32.Delf virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine VHO:Trojan.Win32.Delf?


File Info:

name: A7E7845FD83E9E6C5C3A.mlw
path: /opt/CAPEv2/storage/binaries/989d27a482717a242cc7a1cae9f1ba99b7e4281a0383dfd2e833e8d13092e349
crc32: 902BCF74
md5: a7e7845fd83e9e6c5c3aaf0668dc2aae
sha1: 77583989cd0c6793589f4e7d4883070b5bcdebde
sha256: 989d27a482717a242cc7a1cae9f1ba99b7e4281a0383dfd2e833e8d13092e349
sha512: f13a21b46db2116bd1ff3ac12d730f20b920e669759c8ea1d48430a4276fe7ea017fd633d72a0d1a31e63006aa353349f47afb51ae1aa5f48a50b90cff80dee0
ssdeep: 96:kDsrX6tfMPFE+azj5fcfnp32CCRkrMsixm/gaVqBkRqKV/yEEh4e/WkHNKgMkX:kWu2F9EYpmaAsiE/SBjI/y1h4hg1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFB2E8D43AC86B22E37B9E3195F54091BCB8B1213C1ADE0F5299438A1D737D1C674B67
sha3_384: 8f19c8d777023ec2477d4151fc25ef57747fe172413f76310a6b77e1352dc260cd33cbdd832285f1df37288176c5c3a2
ep_bytes: 558d6c248881ecd408000053565733db
timestamp: 2014-01-27 12:19:18

Version Info:

0: [No Data]

VHO:Trojan.Win32.Delf also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.a7e7845fd83e9e6c
CAT-QuickHealDownloader.Upatre.27298
McAfeeGenericRXRZ-CQ!A7E7845FD83E
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan-Downloader ( 004941701 )
Cybereasonmalicious.fd83e9
CyrenW32/Upatre.NG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Delf.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.frlegi
AvastWin32:Upatre-V [Trj]
TencentTrojan.Win32.Delf.wa
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
DrWebTrojan.DownLoad3.33424
ZillyaTrojan.Waski.Win32.3906
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.fois
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.35392A5
MicrosoftTrojan:Win32/Zbot.VHO!MTB
GDataWin32.Trojan.PSE.19GSOAU
AhnLab-V3Trojan/Win.Upatre.R476095
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34606.bqX@aeybIUdi
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=80)
VBA32Trojan.Download
MalwarebytesMalware.AI.2840754179
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingSpyware.Zbot!8.16B (RDMK:cmRtazoF4BqdA/D/N1o)
YandexTrojan.Delf!x3yOfYLFlis
IkarusPacker.Win32.Krap
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.B!tr
AVGWin32:Upatre-V [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove VHO:Trojan.Win32.Delf?

VHO:Trojan.Win32.Delf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment