Malware

VirTool:Win32/DelfInject!L information

Malware Removal

The VirTool:Win32/DelfInject!L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/DelfInject!L virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/DelfInject!L?


File Info:

crc32: 29FDB462
md5: c6ec788b228aac5a6642aca29eb308b4
name: windowsserver.exe
sha1: d0528466e6afb7008acf1c021a011d53788e7f11
sha256: dbf5741678b4d53f7f23a3471f9ec962317e9da3382357616d543380ff715723
sha512: 7aa6ab3ab64617579b9fcf93cd8b50f7ed80ab923d2f5de880c04c120f8618bf262bcc7409355b09925e1b559dbdf66262d6a405c0344fb730d244b840a60eac
ssdeep: 12288:BSg5VZxeIqOwBKXjUkNg07YS7tkEcc67iU1+deTi+lTLLbQe:BfjeIqOwB4pGPSxFjU1rW+lTLLR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2005-2017 x96f6x4e0ex58f9x8f6fx4ef6
InternalName: xfplay
FileVersion: 9.9.9.5
CompanyName: x96f6x4e0ex58f9x8f6fx4ef6
Comments: x5f3ax5927x7684x591ax5a92x4f53P2Px7f51x7edcx64adx653ex5668 www.xfplay.com
ProductName: xfplay
ProductVersion: 9.9.9.5
FileDescription: x5f71x97f3x5148x950b
OriginalFilename: xfplay.exe
Translation: 0x0000 0x04b0

VirTool:Win32/DelfInject!L also known as:

MicroWorld-eScanGen:Variant.Fugrafa.1938
FireEyeGeneric.mg.c6ec788b228aac5a
Qihoo-360Win32/Backdoor.814
ALYacGen:Variant.Fugrafa.1938
MalwarebytesBackdoor.Hupigon
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Hupigon.l566
SangforMalware
K7AntiVirusTrojan ( 00536e5e1 )
BitDefenderGen:Variant.Fugrafa.1938
K7GWTrojan ( 00536e5e1 )
Cybereasonmalicious.b228aa
BitDefenderThetaGen:NN.ZelphiF.34084.SG0@a0ByOTob
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
BaiduWin32.Trojan.Hupigon.b
TrendMicro-HouseCallTROJ_GEN.R002C0DB620
AvastWin32:Malware-gen
GDataGen:Variant.Fugrafa.1938
KasperskyBackdoor.Win32.Delf.aun
AlibabaBackdoor:Win32/DelfInject.d5436af9
NANO-AntivirusTrojan.Win32.Delf.edulxj
RisingBackdoor.Gpegion!1.6634 (CLOUD)
Ad-AwareGen:Variant.Fugrafa.1938
SophosMal/Behav-141
ComodoTrojWare.Win32.Hupigon.KW@4xcj16
F-SecureBackdoor.BDS/Hupigon.Gen
DrWebTrojan.DownLoader29.38161
ZillyaBackdoor.Delf.Win32.19819
TrendMicroTROJ_GEN.R002C0DB620
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
CMCBackdoor.Win32.Delf!O
EmsisoftGen:Variant.Fugrafa.1938 (B)
F-ProtW32/DelfInject.A.gen!Eldorado
JiangminBackdoor.Delf.pm
WebrootW32.Malware.Gen
AviraBDS/Hupigon.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Fugrafa.D792
ZoneAlarmBackdoor.Win32.Delf.aun
MicrosoftVirTool:Win32/DelfInject.gen!L
TACHYONTrojan/W32.DP-Agent.736768.G
AhnLab-V3Trojan/Win32.Delf.C1553036
Acronissuspicious
McAfeeGenericRXCI-YQ!C6EC788B228A
MAXmalware (ai score=88)
VBA32MalwareScope.Trojan-PSW.Game.16
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Hupigon.NZJ
TencentMalware.Win32.Gencirc.10b3d73a
YandexBackdoor.Delf!tmgcRSI5rUY
SentinelOneDFI – Malicious PE
FortinetW32/Injector.fam!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.52285.susgen

How to remove VirTool:Win32/DelfInject!L?

VirTool:Win32/DelfInject!L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment