Crack

Win32/HackTool.Delf.NCE information

Malware Removal

The Win32/HackTool.Delf.NCE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HackTool.Delf.NCE virus can do?

  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/HackTool.Delf.NCE?


File Info:

name: E2D08987BE2337A6397B.mlw
path: /opt/CAPEv2/storage/binaries/9311ba9bbf3ad1cb439555093e7006eb167ae9af0701eb892f7b32b1f726ad3d
crc32: 6AF73436
md5: e2d08987be2337a6397b5845509048cb
sha1: eaab9177020ac7fa77fc5c7a5d21af8abe6b84b7
sha256: 9311ba9bbf3ad1cb439555093e7006eb167ae9af0701eb892f7b32b1f726ad3d
sha512: 6661d5d375991e70ea56023bac936ee606964ab5587d5cd3306b914c0fababf04cad30047ef80a21c730a149bf004619da8f84f035fe0060ef5a84c4d49b90c1
ssdeep: 196608:jto7itMvFiEXTXIsjR+x2Aty/bXxJP55zD6Tad03y6rV5:HMvFiEXsTy/jTTzD89PH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185763371D711CCB5C4325A34C31BE9B9BC356E080ABC989A30FE6C6DECB27563D09696
sha3_384: 016b6fbedc4f9e4adce0204df9403c46bac666fbffc3fef6c4158cdc6bf2507f9c58f8fae1186a53ac8fd54d292ce4ec
ep_bytes: 558bec83c4f0b888534200e824f2fdff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: Makish115
FileDescription: Generator_Virus_v2 2 Installation
FileVersion: 2
LegalCopyright: Makish115
Translation: 0x0409 0x04e4

Win32/HackTool.Delf.NCE also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.e2d08987be2337a6
CAT-QuickHealTrojan.Dynamer.D9
McAfeeArtemis!E2D08987BE23
CylanceUnsafe
SangforTrojan.Win32.Face.A
K7AntiVirusPassword-Stealer ( 0047e7de1 )
AlibabaHackTool:Win32/Hesv.df0cb684
K7GWPassword-Stealer ( 0047e7de1 )
Cybereasonmalicious.7020ac
CyrenW32/AccPhish.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/HackTool.Delf.NCE
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.47346322
NANO-AntivirusTrojan.Win32.AccPhish.entpyc
MicroWorld-eScanTrojan.GenericKD.47346322
AvastWin32:Dropper-gen [Drp]
Ad-AwareTrojan.GenericKD.47346322
EmsisoftTrojan.GenericKD.47346322 (B)
ComodoMalware@#1gsssh0t97sgp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosGeneric PUA OK (PUA)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.47346322
AviraTR/PHP.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1C2031
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.GenericKD.47346322
MAXmalware (ai score=87)
VBA32Trojan.Zpevdo
TrendMicro-HouseCallTROJ_GEN.R002H0CK521
IkarusBackdoor.MSIL
eGambitUnsafe.AI_Score_100%
AVGWin32:Dropper-gen [Drp]
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq

How to remove Win32/HackTool.Delf.NCE?

Win32/HackTool.Delf.NCE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment