Malware

Win32/Delf.NGB (file analysis)

Malware Removal

The Win32/Delf.NGB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.NGB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Delf.NGB?


File Info:

name: E5E7534061DE53EA1814.mlw
path: /opt/CAPEv2/storage/binaries/a97badcb83d0b0b0db73a2ffad44bf6d97f709233d0e23e5415099080c8e8afe
crc32: B77C14B4
md5: e5e7534061de53ea18146d6a1992de72
sha1: 5ea7ea51523eb55ed215507e83ef81c8e09099b6
sha256: a97badcb83d0b0b0db73a2ffad44bf6d97f709233d0e23e5415099080c8e8afe
sha512: 3fb71e0d8efaab636826d82be3f87ac001066f7e8760992e470b10182a9b905c39623d25ab81640cfddceb15a20f1137dc79afd7044f9947bdc6467a3b24308e
ssdeep: 768:ukIClqcaQfaqgwrKKDyHFc3Z6uTrfut9VvhxCdD9hA1BFBf:VlqcaQfaq8fy3ZH6vB1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133A36E17E5D1C132C800D4FE5C2DB625FA7B2EF33E8915B177BA5DA9AC253824D4C06A
sha3_384: b6b614807facbf10accbb4c43d93bd05ed3a89cd95dd0072e2d95de2e43e2292d54952f2c6821c57706e96b1a45b1f3b
ep_bytes: 558bec83c4e053565733c08945e08945
timestamp: 2004-01-23 23:39:42

Version Info:

0: [No Data]

Win32/Delf.NGB also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
FireEyeGeneric.mg.e5e7534061de53ea
McAfeeArtemis!E5E7534061DE
ZillyaWorm.Delf.Win32.3434
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 003b1b581 )
AlibabaWorm:Win32/SuspPack.ed97b3a1
K7GWTrojan ( 003b1b581 )
Cybereasonmalicious.1523eb
CyrenW32/SuspPack.C.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Delf.NGB
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Drop.bxpfsw
SophosMal/Generic-S
DrWebTrojan.MulDrop.19793
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
JiangminWorm.Generic.brer
Antiy-AVLTrojan/Generic.ASMalwFH.5174
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGeneric.Trojan.PSEB.80RWC9
GoogleDetected
AhnLab-V3Malware/Gen.Generic.C2836633
MalwarebytesMalware.AI.694272467
RisingWorm.Delf!8.1B3 (TFE:4:FuNPLGcvLQL)
YandexWorm.Delf!Ixb5GlZKC70
IkarusTrojan-Dropper.Delf
FortinetW32/Delf.NGB!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Delf.NGB?

Win32/Delf.NGB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment