Malware

Win32/Delf.NBX removal guide

Malware Removal

The Win32/Delf.NBX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.NBX virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

xred.mooo.com
freedns.afraid.org

How to determine Win32/Delf.NBX?


File Info:

crc32: 341DADAF
md5: 118ddf3c61e3be81e84573de6ac3ac82
name: 118ddf3c61e3be81e84573de6ac3ac82.exe
sha1: d7bd5849ab33043eebbe14dad2e88909e483c65d
sha256: 95653f6ef4c3ba595bcad827e407926ce6b524a5b00904c8a663cc145b53dbc0
sha512: efab2491f6dcad5cfa6994ab864e2a777a84a49a98897e2fe92e9c8d1a816bd59664bad8105988954a39ad7c624facc60b47779ef126f7fd391664f7cadc612e
ssdeep: 49152:7nsHyjtk2MYC5GDfMV1EGwQpoLohT4htvqbuT088mtzANJIKshr1kQkBe+UjXGIG:7nsmtk2adooINUUjW1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Win32/Delf.NBX also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.DownLoader22.9658
MicroWorld-eScanDropped:Trojan.GenericKD.32840913
CAT-QuickHealW32.Delf.NB4
Qihoo-360Win32/Virus.Synaptics.A
McAfeeGenericRXCB-VC!118DDF3C61E3
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Trojan.GenericKD.32840913
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9ab330
TrendMicroVirus.Win32.NAPWHICH.B
BitDefenderThetaGen:NN.ZelphiCO.34090.TI0@ai3GchnH
F-ProtW32/Zorex.A
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Delf-6899401-0
GDataWin32.Application.PUPStudio.B
KasperskyBackdoor.Win32.DarkKomet.hqxy
AlibabaBackdoor:Win32/DarkKomet.802354ad
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
AegisLabTrojan.Win32.DarkKomet.m!c
RisingBackdoor.Agent!1.BF3D (CLOUD)
Ad-AwareDropped:Trojan.GenericKD.32840913
SophosElReceptor Keyboard Hook (PUA)
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
ZillyaTrojan.Delf.Win32.76144
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.vh
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.118ddf3c61e3be81
EmsisoftDropped:Trojan.GenericKD.32840913 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Backdoor.OAZM-5661
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraWORM/Dldr.Agent.gqrxn
Antiy-AVLTrojan[Downloader]/Script.AGeneric
Endgamemalicious (high confidence)
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
MicrosoftWorm:Win32/AutoRun.XXY!bit
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
VBA32BScope.Backdoor.DarkKomet
ALYacDropped:Trojan.GenericKD.32840913
MAXmalware (ai score=86)
MalwarebytesTrojan.Agent
ESET-NOD32Win32/Delf.NBX
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
TencentMalware.Win32.Gencirc.10b8ace3
YandexBackDoor.Optix!
IkarusVirus.Win32.Delf
eGambitUnsafe.AI_Score_100%
FortinetW32/Delf.NBX!tr
AVGOther:Malware-gen [Trj]
AvastWin32:Zorex-E [Wrm]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Delf.NBX?

Win32/Delf.NBX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment