Malware

What is “Win32/Delf.BKO”?

Malware Removal

The Win32/Delf.BKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.BKO virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Delf.BKO?


File Info:

crc32: 13476056
md5: 599a83efe96b94407643276d925ff305
name: signed.exe
sha1: c8b5df0e3a3f9ff9982a92b324b8642b97bba86f
sha256: eef9dc091dcbf7aa38a3c683b9da35e878d3ddb365e0e2c560d581126aa17b18
sha512: 0ab36289dc587aef648ffba7ca8356aaa6192db8fb648dff69d569702bdac28787cd2703de7cc3a6152accdcc27f359e6fa0cf475c3a4e4ecc1bb2dfaf6eb53a
ssdeep: 98304:iO6kD988JRQwmUJ4wNfWihg6mA27CAgudSSpR94:N6UK8JWwme4afxhg6m2cAsf4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: all rights reserved
FileVersion: 1.4.7.1
CompanyName: lib collection archive march
LegalTrademarks: collection company all rights
Comments: lib collection archive march
ProductName: lib collection 2020
Translation: 0x0409 0x04e4

Win32/Delf.BKO also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.33544113
FireEyeTrojan.GenericKD.33544113
Qihoo-360Win32/Trojan.Dropper.45c
McAfeeArtemis!599A83EFE96B
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33544113
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
ClamAVWin.Malware.Score-6931191-0
GDataTrojan.GenericKD.33544113
KasperskyHEUR:Trojan-Dropper.Win32.Agent.gen
AegisLabTrojan.Win32.Agent.b!c
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
Ad-AwareTrojan.GenericKD.33544113
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1046052
Invinceaheuristic
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.33544113 (B)
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1046052
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFD7B1
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.gen
MicrosoftTrojan:Win32/Bluteal!rfn
ALYacTrojan.GenericKD.33544113
MAXmalware (ai score=81)
PandaTrj/CI.A
ESET-NOD32Win32/Delf.BKO
TrendMicro-HouseCallTROJ_GEN.R011H0CCG20
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Delf.BKO?

Win32/Delf.BKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment