Malware

Win32/Delf.OHC removal tips

Malware Removal

The Win32/Delf.OHC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.OHC virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Anomalous binary characteristics

Related domains:

mzo.hopto.org

How to determine Win32/Delf.OHC?


File Info:

crc32: BE202A0D
md5: fa8ca5694f859b5c712f9a7926b8d9e7
name: FA8CA5694F859B5C712F9A7926B8D9E7.mlw
sha1: 646cd61fcbfb1c5ced3f48731e1ddbed6775d72f
sha256: ab56c3e9143fe27240eecc7f8efaa3bef40514c34944c37fbd8537321d7dc0f9
sha512: a743c76b0045d721e70b1bde04f16cb505401e3d605235b6a4f5cde0a9dbe9edc3f91ce72f398f002ea1ffa6bd5305c704aaf2e0662dfd692d7df259c868402e
ssdeep: 1536:q3iPqqQosZmi0kHCfNTU0MzshiHEc/rqx3R:/GZJHCfNTU7wEf2x3R
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Internation Systems Incorporated
InternalName: Normalize.exe
FileVersion: 10.0.1.434
CompanyName: Internation Incorporated
LegalTrademarks: xaeInternation Systems Incorporated
Comments: by Jhh tim - 2012
ProductName: Intelxae
ProductVersion: 10.0.1.434
FileDescription: File Folder
OriginalFilename: Intelxae.exe
Translation: 0x0809 0x04e4

Win32/Delf.OHC also known as:

LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.7454
ALYacGen:Trojan.Heur.dG0@tHPMC2hib
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.4505
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
ESET-NOD32a variant of Win32/Delf.OHC
APEXMalicious
AvastWin32:Delfcrypt-AI [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.dG0@tHPMC2hib
NANO-AntivirusTrojan.Win32.Winlock.crkzwj
MicroWorld-eScanGen:Trojan.Heur.dG0@tHPMC2hib
TencentMalware.Win32.Gencirc.114cc964
Ad-AwareGen:Trojan.Heur.dG0@tHPMC2hib
SophosMal/Generic-L
ComodoMalware@#niaebyhl3r93
BitDefenderThetaAI:Packer.5B93F6121D
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-CWM!FA8CA5694F85
FireEyeGeneric.mg.fa8ca5694f859b5c
EmsisoftGen:Trojan.Heur.dG0@tHPMC2hib (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Blocker.aeg
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117111
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.15092F
KingsoftWin32.HeurC.KVM007.a.(kcloud)
MicrosoftBackdoor:Win32/Tapazom.A
ArcabitTrojan.Heur.EBD1C3B
SUPERAntiSpywareTrojan.Agent/Gen-Blocker
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.dG0@tHPMC2hib
AhnLab-V3HEUR/Fakon.mwf.X1381
McAfeeGenericR-CWM!FA8CA5694F85
MAXmalware (ai score=87)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.2289403956
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.85 (RDML:UMV05100rvJSImvkjq1j7w)
YandexTrojan.GenAsa!PqXTSCD7ssQ
IkarusBackdoor.Win32.Tapazom
FortinetW32/SPNR.28K512!tr
AVGWin32:Delfcrypt-AI [Trj]
Paloaltogeneric.ml

How to remove Win32/Delf.OHC?

Win32/Delf.OHC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment