Malware

How to remove “Win32/Delf.NZQ”?

Malware Removal

The Win32/Delf.NZQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.NZQ virus can do?

  • Creates RWX memory
  • Loads a driver
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Delf.NZQ?


File Info:

crc32: 0BAC614B
md5: f6fb899ca4c9fd2b37695e4431259f05
name: F6FB899CA4C9FD2B37695E4431259F05.mlw
sha1: 8058ea1a7834bcf7ae6ad2fdad634d1ab215838a
sha256: 985bd44a6c4c9482234dd18000f168ca7be4c641c69a5f6de1cdc45471bd2100
sha512: 823dffc0f3034ce24235494fed1a2f8366368bc0d5d5676ef0dc202ec5c6e387d783b4a4ff020f512a8d43ba8bc526ae06bc259b0c10d014bdca00d02099343a
ssdeep: 49152:aI9BsBE9UZM4OKsB8X4VhKJ4OKsB8X4VjsB8X4cE9Ud:aI9BsiU+d8Xxd8Xv8XWUd
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Delf.NZQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0008550a1 )
Elasticmalicious (high confidence)
DrWebTool.HideProc.27
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.5885
CylanceUnsafe
ZillyaTrojan.Delf.Win32.52545
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0008550a1 )
Cybereasonmalicious.ca4c9f
CyrenW32/Delf.IQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.NZQ
APEXMalicious
AvastWin32:HideProc-N [PUP]
ClamAVWin.Trojan.Hideproc-77
KasperskyTrojan-Downloader.Win32.Banload.aalpj
BitDefenderGen:Variant.Fugrafa.5885
NANO-AntivirusRiskware.Win32.HideProc.crvalg
MicroWorld-eScanGen:Variant.Fugrafa.5885
TencentMalware.Win32.Gencirc.10b87824
Ad-AwareGen:Variant.Fugrafa.5885
SophosTroj/Ghetifuh-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZelphiF.34236.lxZ@aOrrWxbb
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRTKT_HIDEPROC.BB
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeGeneric.mg.f6fb899ca4c9fd2b
EmsisoftGen:Variant.Fugrafa.5885 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Banload.akge
AviraTR/Rootkit.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.112E4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Fugrafa.5885
AhnLab-V3Trojan/Win.Banload.R447588
Acronissuspicious
McAfeeGenericRXAA-AA!F6FB899CA4C9
MAXmalware (ai score=81)
VBA32BScope.TrojanDownloader.Banload
PandaTrj/Genetic.gen
TrendMicro-HouseCallRTKT_HIDEPROC.BB
RisingRootKit.Win32.HideProc.l (CLASSIC)
YandexTrojan.GenAsa!nT9bLJVyuj4
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.NZQ!tr
AVGWin32:HideProc-N [PUP]

How to remove Win32/Delf.NZQ?

Win32/Delf.NZQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment