Malware

Should I remove “Win32/Delf.NPB”?

Malware Removal

The Win32/Delf.NPB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.NPB virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Creates a copy of itself

How to determine Win32/Delf.NPB?


File Info:

name: E34410316BBE730D2440.mlw
path: /opt/CAPEv2/storage/binaries/03d9a32eeaa0618c0756e5c4316a8d53b43d936884a5236e7c31cb2b31c07a90
crc32: 0F0F4B3B
md5: e34410316bbe730d2440676b9bd97a84
sha1: ed720ed6e43ee0a2c407730fc61bac5b59203c99
sha256: 03d9a32eeaa0618c0756e5c4316a8d53b43d936884a5236e7c31cb2b31c07a90
sha512: 78bf5c4d08882b534ff9756ed2dc35b287936279f584ad91e6865dee1f29992dd6e63cd3878826d94b33860538f017e1d372165a61243e9aa8e872c5da1edb82
ssdeep: 1536:01Rjr6PKT/wJNr0aCraUFMM40dE6N9gE1QetDwOpF0kV:01RjuW/sCWUF+0/9TQcDwO3PV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105832722F6C0CA73E1610ABC4C5792E5016E76713EB9241B7AE60B8DDCB96C19E1F1C7
sha3_384: 44c84eabe0f40f987b8c4e67338fe5dfea55afc39347779c28c91981ca3fa45ed8ab30af39975d80dba3db43e1ccd73d
ep_bytes: 558becb9160000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.5
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0809 0x04e4

Win32/Delf.NPB also known as:

LionicTrojan.Win32.OnLineGames.mA2A
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Delf.Inject.Z
FireEyeGeneric.mg.e34410316bbe730d
SkyhighBehavesLike.Win32.Ransomware.mh
McAfeeBackDoor-EGV
ZillyaTrojan.Agent.Win32.16780
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0009ae161 )
AlibabaTrojan:Win32/Fsysna.beaa3996
K7GWTrojan ( 0009ae161 )
Cybereasonmalicious.16bbe7
VirITTrojan.Win32.Generic.CAAF
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.NPB
APEXMalicious
TrendMicro-HouseCallTROJ_INVADER.SM
ClamAVWin.Trojan.LogonInvader-1
KasperskyTrojan.Win32.Fsysna.rmq
BitDefenderTrojan.Delf.Inject.Z
NANO-AntivirusTrojan.Win32.LogonInvader.vekx
AvastWin32:Delf-MPY [Trj]
TencentMalware.Win32.Gencirc.10b2a751
EmsisoftTrojan.Delf.Inject.Z (B)
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.Click2.28853
VIPRETrojan.Delf.Inject.Z
TrendMicroTROJ_INVADER.SM
Trapminemalicious.moderate.ml.score
SophosMal/Generic-D
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=99)
JiangminBackdoor/Agent.brxl
GoogleDetected
AviraBDS/Backdoor.Gen
VaristW32/Trojan.MXCZ-0641
Antiy-AVLTrojan/Win32.LogonInvader
Kingsoftmalware.kb.a.1000
MicrosoftVirTool:Win32/DelfInject.gen!X
XcitiumTrojWare.Win32.TrojanSpy.KeyLogger.~CQ@18b7fb
ArcabitTrojan.Delf.Inject.Z
ViRobotTrojan.Win32.Agent.88576.G
ZoneAlarmTrojan.Win32.Fsysna.rmq
GDataTrojan.Delf.Inject.Z
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C89314
BitDefenderThetaAI:Packer.9FECD70721
ALYacTrojan.Delf.Inject.Z
TACHYONTrojan/W32.DP-Fsysna.88576
VBA32Trojan.LogonInvader
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Win32.Delf.dzk (CLASSIC)
YandexTrojan.GenAsa!/rUkpNV9Emg
IkarusVirTool.Win32.DelfInject
MaxSecureTrojan.W32.Invader.a
FortinetW32/Generic.AC.1FA117!tr
AVGWin32:Delf-MPY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Delf.NPB

How to remove Win32/Delf.NPB?

Win32/Delf.NPB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment