Malware

Win32/Delf.NPF removal

Malware Removal

The Win32/Delf.NPF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.NPF virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Delf.NPF?


File Info:

name: C293FF633802BB8ECEA9.mlw
path: /opt/CAPEv2/storage/binaries/a8e52d6d0c6940bf6f05a6ad6c3d530c4da71f3c4bfeb6991b044990ee2c0774
crc32: C4E61DCD
md5: c293ff633802bb8ecea95a07abac3118
sha1: 8a468151a245ffde68f822d3f6047e9f5f961534
sha256: a8e52d6d0c6940bf6f05a6ad6c3d530c4da71f3c4bfeb6991b044990ee2c0774
sha512: 35f84b234fcdbf9cc2f8e2e05fe042139090e8c3c02ce0fb6f800a7dda2a3e64477e119dc79567dc4d0d371b7941aac4921330a7dfb2070e28d4a75aec92b810
ssdeep: 6144:EhafiAx+1zwjJHd6vB/UNMibXIL3mt1d8:X6Ag1zm6cNMibXIL3mt1d8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196253E15ABF60B26F2F74E30A8AA5974B832BC52BE01C7990546C64C0C66F51DD72F2F
sha3_384: 666c5586b86b01c8c7b40bfa58a7f70e60ea3e6c182f76f12ae7435cba677f5b10b6c4969f14dd2c5b8f2df5d2f78804
ep_bytes: 558becb9070000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Delf.NPF also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.96296
ClamAVWin.Worm.Generickdz-10012896-0
FireEyeGeneric.mg.c293ff633802bb8e
CAT-QuickHealWorm.Antavmu .S29499354
SkyhighBehavesLike.Win32.Generic.dz
McAfeeGenericRXTD-AF!C293FF633802
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Delf.Win32.5413
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.33802b
BitDefenderThetaAI:Packer.785F861A1E
VirITWorm.Win32.DelfGen.DQC
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Delf.NPF
ZonerProbably Heur.ExeHeaderP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Win32.Injector.gen
BitDefenderTrojan.GenericKDZ.96296
NANO-AntivirusTrojan.Win32.Antavmu.daxbyw
AvastWin32:TrojanX-gen [Trj]
EmsisoftTrojan.GenericKDZ.96296 (B)
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.Siggen6.19898
VIPRETrojan.GenericKDZ.96296
TrendMicroPossible_Virus
Trapminemalicious.high.ml.score
SophosW32/Delf-HPC
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Antavmu.dgo
AviraTR/Dldr.Delphi.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Antavmu
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Generic.D17828
ZoneAlarmHEUR:Trojan-Dropper.Win32.Injector.gen
GDataWin32.Trojan.Mumador.A
VaristW32/Trojan.BULQ-1908
AhnLab-V3Malware/Win.Generic.C5605801
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacTrojan.GenericKDZ.96296
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPossible_Virus
RisingWorm.Delf!8.1B3 (TFE:4:yInPxZkuhvF)
YandexTrojan.GenAsa!duuQP43g4yE
IkarusWorm.Win32.Delf
FortinetW32/Delf.NGO!worm
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/Delf.NPF?

Win32/Delf.NPF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment