Malware

Win32/Delf.OIN (file analysis)

Malware Removal

The Win32/Delf.OIN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.OIN virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Delf.OIN?


File Info:

crc32: B683D526
md5: d230adae6f4f290b6b1d4401b13c5bd5
name: test.exe
sha1: e8588a3c0b0dd861bc15ace3cd9ca6afa07d9ff2
sha256: 9d5dc82737baf146c635f45e409ac06e17f7c065d94f2d5be23037627aeabbac
sha512: caa26901bb4442dd49f82fd9e6edbdcd83645203f1bd0615532f98a1d07aa8a8ac8e79310934788fea7269d703baa1f1b34baab78190566e571b3570c8830a34
ssdeep: 12288:qJi16yAc5TmNGxochOYyE0WLW3IzFTtJQa81h:qscynTD2KTPxTtJuf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Delf.OIN also known as:

MicroWorld-eScanTrojan.GenericKD.40697991
CAT-QuickHealTrojan.GenericCS.S209117
ALYacTrojan.GenericKD.40697991
CylanceUnsafe
ZillyaTrojan.Delf.Win32.57485
BitDefenderTrojan.GenericKD.40697991
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
TheHackerTrojan/Delf.oin
TrendMicroTROJ_GEN.R01FC0PK418
NANO-AntivirusTrojan.Win32.MlwGen.bcbfqc
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R01FC0PK418
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-485474
GDataTrojan.GenericKD.40697991
KasperskyHEUR:Trojan.Win32.Generic
ViRobotTrojan.Win32.Z.Delf.551424.AE
RisingTrojan.Delf!8.67 (CLOUD)
Ad-AwareTrojan.GenericKD.40697991
SophosMal/Generic-S
ComodoMalware@#e11dxynbr2ge
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader7.30425
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionGenericR-APN!D230ADAE6F4F
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.40697991 (B)
IkarusTrojan.Win32.Spy2
CyrenW32/Trojan.KGQD-6274
WebrootW32.Trojan.Gen
AviraTR/ATRAPS.Gen
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Occamy.C
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Agent.R200351
McAfeeGenericR-APN!D230ADAE6F4F
VBA32Trojan.Downloader
MalwarebytesTrojan.Agent.XN
PandaGeneric Malware
ArcabitTrojan.Generic.D26D0087
ESET-NOD32Win32/Delf.OIN
TencentWin32.Trojan.Generic.Wofg
YandexTrojan.Agent!i0ET4n2onTo
SentinelOnestatic engine – malicious
FortinetW32/Delf.OIN!tr
AVGWin32:Malware-gen
Cybereasonmalicious.e6f4f2
Paloaltogeneric.ml
CrowdStrikemalicious_confidence_70% (D)
Qihoo-360HEUR/QVM05.1.FCB9.Malware.Gen

How to remove Win32/Delf.OIN?

Win32/Delf.OIN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment