Malware

Win32/Delf.NRF removal guide

Malware Removal

The Win32/Delf.NRF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.NRF virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Win32/Delf.NRF?


File Info:

name: F87627B3520EF4317692.mlw
path: /opt/CAPEv2/storage/binaries/b320d36c6514f92475b8d09029aa33753f787022d993e4477b14036a2359b537
crc32: A5AEC6BF
md5: f87627b3520ef43176926b9f355f70d2
sha1: aba62441eabe6a53391c4abc7312a44d21ae7d6f
sha256: b320d36c6514f92475b8d09029aa33753f787022d993e4477b14036a2359b537
sha512: 808e581407a98318ec3be902f9782282cfb09c0c2d0e4ae3366075b4b92afe4ece9fd013523d2368821da00b49d75e5fff8030e5b59ad20cd729d81f798e213d
ssdeep: 196608:rZCIzmcbEi9pR6cPIjZ1B4QouKtJZjNxnFClZtCyEjm7PogH7jNoNPA:NmeR/6cQ15cLfnaZtdEyToA7j0A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BFB6330C369D9DBCC03E51386057868FE86935A03346AA2EEEF5D5D3862B4FC0D446FA
sha3_384: d8e69cfd887be864406da0302713f0a35aabd4df6528abd4f0f91a47af184e0f26a47e8daa814cf276261a354450e827
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Delf.NRF also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGenPack:Trojan.Agent.DQQD
FireEyeGeneric.mg.f87627b3520ef431
McAfeeGenericRXAA-AA!F87627B3520E
CylanceUnsafe
ZillyaBackdoor.Wabot.Win32.2310
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGenPack:Trojan.Agent.DQQD
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaAI:Packer.FB60C6DA1D
CyrenW32/Trojan.GPL.gen!Eldorado
SymantecW32.Wabot
ESET-NOD32a variant of Win32/Delf.NRF
BaiduWin32.Backdoor.Wabot.a
APEXMalicious
AvastWin32:Zbot-LV [Trj]
ClamAVWin.Trojan.Wabot-7053120-0
KasperskyBackdoor.Win32.Wabot.a
RisingWorm.Chilly!1.661C (CLASSIC)
Ad-AwareGenPack:Trojan.Agent.DQQD
SophosML/PE-A
ComodoBackdoor.Win32.Wabot.A@4knk5y
DrWebTrojan.MulDrop6.64369
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
TrendMicroBackdoor.Win32.WABOT.SMD
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
EmsisoftGenPack:Trojan.Agent.DQQD (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm.Generic.gbw
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.C66A
MicrosoftBackdoor:Win32/Wabot.A
GDataWin32.Trojan.PSE.MIA95L
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Wabot.R431896
Acronissuspicious
VBA32Backdoor.Wabot
ALYacGenPack:Trojan.Agent.DQQD
MalwarebytesBackdoor.Wabot
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
TencentTrojan.Win32.Wabot.a
YandexBackdoor.Wabot!9XOZJESPPLY
MAXmalware (ai score=84)
FortinetW32/Delf.NRF!tr
AVGWin32:Zbot-LV [Trj]
Cybereasonmalicious.3520ef

How to remove Win32/Delf.NRF?

Win32/Delf.NRF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment