Virus

What is “Virus.Win32.Delf.62976”?

Malware Removal

The Virus.Win32.Delf.62976 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Delf.62976 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Virus.Win32.Delf.62976?


File Info:

name: 5F9B8B1037387CF2C6D0.mlw
path: /opt/CAPEv2/storage/binaries/cabce59a9e2ad8499cd6a88909a14f5d6a0cc71339f038df3660b92d08a61950
crc32: 96611AD0
md5: 5f9b8b1037387cf2c6d0a658c75c52b7
sha1: aef456bbdff6a4982a42f0bfc49d661c3ee4d0e3
sha256: cabce59a9e2ad8499cd6a88909a14f5d6a0cc71339f038df3660b92d08a61950
sha512: be1303c475aaf19572486ef6b3257164574004cbb9e3fb7c012cf74f8ba4ed8783560851e8453a07ec6b50bd8cf9faed725a8d9bd301ab31b646c89be2b3e5e9
ssdeep: 6144:StfDEsjPhczUT2IoJoOYlZZ3X97WTSsdbusLgKGFAWadzmQX37v:SbdroJoO0Z1X96kegKiAWQj7v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CAB43951F3E404F5F0B79A388D768512DAB67C691B20DA8F13A8265A1E337D18D39F32
sha3_384: 4358a5a7545a50db5b9fe7616bff8b1e15b81f62ca7d49d9ad978d07ead40f4329dbf1166625b75095ed90475cd5015a
ep_bytes: 558bec83c4f0b83c944000e8dcacffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virus.Win32.Delf.62976 also known as:

BkavW32.logo_1.PE
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47286069
FireEyeGeneric.mg.5f9b8b1037387cf2
CAT-QuickHealTrojan.GenericIH.S24445994
ALYacTrojan.GenericKD.47286069
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderTrojan.GenericKD.47286069
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.037387
BitDefenderThetaAI:Packer.5E2494F41D
CyrenW32/Cardo.A
ESET-NOD32Win32/Viking.AM
TrendMicro-HouseCallPE_LOOKED.G
KasperskyVirus.Win32.Delf.62976
NANO-AntivirusVirus.Win32.Delf.flfw
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKD.47286069
EmsisoftTrojan.GenericKD.47286069 (B)
ComodoWin32.Viking.AM~clean@3ax3
DrWebWin32.HLLP.Logo.62976
ZillyaTrojan.Lmir.Win32.3
TrendMicroPE_LOOKED.G
McAfee-GW-EditionBehavesLike.Win32.Fasong.hh
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + W32/LegMir-U
APEXMalicious
JiangminWorm/Zorin.b
AviraW32/Cardo.A
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASBOL.29A8
MicrosoftVirus:Win32/Viking.JX
GDataWin32.Trojan.PSE.TLQCHU
CynetMalicious (score: 100)
AhnLab-V3Win32/Lemir.62976
Acronissuspicious
McAfeeW32/HLLP.n.j
VBA32Virus.Win32.Delf.62976
MalwarebytesMalware.AI.3581986639
PandaW32/Viking.PS
RisingWorm.Viking.ac (CLASSIC)
YandexTrojan.GenAsa!S1dREYVu8UQ
FortinetW32/Leox.A
AVGWin32:Delf-YZ [Trj]
AvastWin32:Delf-YZ [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.W32.Delf.AI

How to remove Virus.Win32.Delf.62976?

Virus.Win32.Delf.62976 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment