Malware

Should I remove “VirTool:Win32/DelfInject!AH”?

Malware Removal

The VirTool:Win32/DelfInject!AH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/DelfInject!AH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/DelfInject!AH?


File Info:

crc32: 7AB737B9
md5: ccb994a6bca84d950698bbd4d552284c
name: service.exe
sha1: 2054d566a5226a93ff7595cb784ab4916a0157e6
sha256: 3d375c40a687f30a48ac403b22514f14ab114fa34a5f77fe6555d1a46c42d9f4
sha512: 02741df21d159c1e766e1c07a7c085cd3a51ead7e471de28f3b982bb05925091264930b548ed525842c92f4336329e85c6fd796b77b04bb077eebde2ce800bbe
ssdeep: 3072:hP5zw1uB0KCffl6CFxw3AAxUSEkSqLQj2Bex3Va5SNBI7s/UtbThDuJgPW8rtO6:hP1w153l6CFyCSE1qL1+agBI7ZbFueH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/DelfInject!AH also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.NTPacker
FireEyeGeneric.mg.ccb994a6bca84d95
McAfeeW32/Sdbot.cf.gen
CylanceUnsafe
VIPRERiskTool.Win32.ProcessPatcher.Nor!cobra (v) (not malicious)
SangforMalware
BitDefenderTrojan.NTPacker
Cybereasonmalicious.6bca84
TrendMicroBKDR_BIFROSE.A
F-ProtW32/Spybot.PHL
SymantecW32.IRCBot
TotalDefenseWin32/Tnega.APVC
APEXMalicious
AvastWin32:Agent-DEI [Trj]
ClamAVWin.Dropper.Delf-564
GDataTrojan.NTPacker
KasperskyPacked.Win32.CPEX-based.c
AlibabaTrojanDropper:Win32/CPEX-based.e6668f73
NANO-AntivirusTrojan.Win32.NtRootKit.fllajz
ViRobotDropper.Agent.1142784
AegisLabTrojan.Win32.Rbot.leZz
Endgamemalicious (high confidence)
EmsisoftTrojan.NTPacker (B)
ComodoTrojWare.Win32.TrojanDropper.ErPack@4hsl
F-SecureRogue:W32/FakeAv.BI
DrWebTrojan.NtRootKit.40
ZillyaBackdoor.CPEX.Win32.1888
Invinceaheuristic
Trapminemalicious.moderate.ml.score
SophosW32/Rbot-Gen
IkarusBackdoor.Win32.Prorat
CyrenW32/DelfInject.A.gen!Eldorado
JiangminTrojanDropper.Delf.hb
WebrootW32.Dropper.Gen
AviraWORM/Mytob.FH
MAXmalware (ai score=100)
Antiy-AVLTrojan[Packed]/Win32.CPEX-based
ArcabitTrojan.NTPacker
ZoneAlarmPacked.Win32.CPEX-based.c
MicrosoftVirTool:Win32/DelfInject.gen!AH
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bifrose.C72278
Acronissuspicious
VBA32Malware-Cryptor.Inject.gen
ALYacTrojan.NTPacker
Ad-AwareTrojan.NTPacker
PandaGeneric Malware
ESET-NOD32Win32/TrojanDropper.ErPack
TrendMicro-HouseCallBKDR_BIFROSE.A
RisingBackdoor.Win32.Rbot.a (CLASSIC)
YandexTrojan.Spybot!6BBWThPL6Y8
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.fam!tr
BitDefenderThetaAI:Packer.45B891371B
AVGWin32:Agent-DEI [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM41.2.001B.Malware.Gen

How to remove VirTool:Win32/DelfInject!AH?

VirTool:Win32/DelfInject!AH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment