Malware

Win32/Delf.UFI removal guide

Malware Removal

The Win32/Delf.UFI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.UFI virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to restart the guest VM
  • Likely virus infection of existing system binary

How to determine Win32/Delf.UFI?


File Info:

name: 0011482E3A1CFAB06D34.mlw
path: /opt/CAPEv2/storage/binaries/dec8ebf05bc58ed587b1afd6f765b5cb3e4384d40d870f796e756687c3416879
crc32: 5C93A57E
md5: 0011482e3a1cfab06d343f4ca92d4c75
sha1: 42b779f33efe96f9a4e7fbae9351fff4437aa184
sha256: dec8ebf05bc58ed587b1afd6f765b5cb3e4384d40d870f796e756687c3416879
sha512: cd98f6e6c041fdd4461a3912d5e51199f567d65fe057aeb723ff74214b64146d9f3fb5e2de533e947825e49916b8ad6710b8cb994202cbf31b08e1745609bca3
ssdeep: 768:A/uB8TdS/VL1sUd16JrrmGOsrMTG/N9GhzXtMunh47apqDBjnoI:iuBVpeesJryUrdOhzdPnuPjno
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179733A61FBD34071E1380EF95C7ECD59903B7E203D33996E26D8BA3D8C795818A0966B
sha3_384: 9a4b1b486366a72d40975b94fcec931e907e23e401f04324f5e9addbee06e08ec30a0d6db546fd18fdc0272aae0df0e8
ep_bytes: 558bec81c48cf6ffff53565733c08985
timestamp: 2019-05-03 18:06:47

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Spooler
FileVersion: 4.0.0.0
InternalName: Server
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Server
ProductVersion: 4.0.0
Translation: 0x0409 0x04e4

Win32/Delf.UFI also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.52229
FireEyeGeneric.mg.0011482e3a1cfab0
CAT-QuickHealTrojan.IgenericIH.S17463031
McAfeeGenericR-REN!0011482E3A1C
CylanceUnsafe
ZillyaTrojan.Delf.Win32.132013
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e3a1cf
BitDefenderThetaAI:Packer.5CF59C4F1C
CyrenW32/Threat-SysVenFak-based!Maxi
ESET-NOD32a variant of Win32/Delf.UFI
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Fsysna.gen
BitDefenderDropped:Generic.Malware.SDg.99F29B7F
MicroWorld-eScanDropped:Generic.Malware.SDg.99F29B7F
TencentMalware.Win32.Gencirc.10cec305
EmsisoftDropped:Generic.Malware.SDg.99F29B7F (B)
ComodoTrojWare.Win32.Spy.Banker.Gen@1qlojk
McAfee-GW-EditionGenericR-REN!0011482E3A1C
SophosGeneric ML PUA (PUA)
JiangminTrojan.Generic.ehacx
AviraTR/Crypt.FKM.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Malex
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Win32.Fsysna.gen
GDataDropped:Generic.Malware.SDg.99F29B7F
AhnLab-V3Malware/Win32.RL_Generic.R326963
VBA32BScope.Trojan.Fsysna
ALYacDropped:Generic.Malware.SDg.99F29B7F
MalwarebytesMalware.AI.681562963
RisingTrojan.Delf!8.67 (RDMK:cmRtazqcGLrIcUvqkHpZxkjiUMUb)
YandexTrojan.GenAsa!Wkrw1vpUc6Y
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Delf.UFI!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Delf.UFI?

Win32/Delf.UFI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment