Trojan

Win32/TrojanClicker.Delf.NKH malicious file

Malware Removal

The Win32/TrojanClicker.Delf.NKH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanClicker.Delf.NKH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/TrojanClicker.Delf.NKH?


File Info:

name: D662E0F781946F128208.mlw
path: /opt/CAPEv2/storage/binaries/7c39dd94ab72877b4b9046ae4735a01234402916de2316fc8e2da56c39d30950
crc32: 89587142
md5: d662e0f781946f12820872a3e1b78c90
sha1: 0c33c2cda8ce52dd44f6261019ca43ccbf1fb300
sha256: 7c39dd94ab72877b4b9046ae4735a01234402916de2316fc8e2da56c39d30950
sha512: 2e1cf047ac2c0bdd5b60a07c4aca6f0442c9191918097b86f5ee34ef4a3ee073dbadbeef230fe2922126be125236fa6f5a962a14383b6deebd8f9ac54034060c
ssdeep: 24576:FHLrxGKIZwKEADWTPK6lySyX19E9PyBzSx/uB661S0C0xytR:XCDEA4Pzc9+xRuCJR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF653383E4C088F9EA58DA310E17F25191B37B061D716054FBEE9DA9CF1B4C58E2F692
sha3_384: 9104e7dbe04a1757e12c922431b9beb49653b48ec7251e08480c9ff669708aa61bf5fbaefa844090d8639223b29cbb46
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: 此安装程序由 Inno Setup 构建。
CompanyName:
FileDescription: windowssetup Setup
FileVersion:
LegalCopyright:
ProductName: windowssetup
ProductVersion:
Translation: 0x0804 0x0000

Win32/TrojanClicker.Delf.NKH also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.lkNW
DrWebTrojan.Siggen2.56468
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Bingoml
McAfeeArtemis!D662E0F78194
Cylanceunsafe
ZillyaTrojan.Agent.Win32.98495
Cybereasonmalicious.da8ce5
CyrenW32/Risk.ZZZW-0943
SymantecTrojan.Gen.2
ESET-NOD32Win32/TrojanClicker.Delf.NKH
APEXMalicious
ClamAVWin.Trojan.Startpage-2357
KasperskyUDS:Trojan.Win32.Bingoml.gen
AlibabaTrojanClicker:Win32/MalwareF.8f33c3b8
NANO-AntivirusTrojan.Win32.Agent.ikmgf
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.StartPage!1.CED5 (CLASSIC)
TACHYONTrojan-Clicker/W32.DP-Agent.434688
F-SecureHeuristic.HEUR/AGEN.1328572
TrendMicroTROJ_CLICKER.CVX
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-PWS.Win32.LdPinch
WebrootW32.Trojan.Malat
AviraHEUR/AGEN.1332580
Antiy-AVLTrojan[Clicker]/Win32.Agent
XcitiumMalware@#1nfk9cglkq2ov
ZoneAlarmHEUR:Trojan.Win32.Bingoml.gen
GoogleDetected
MAXmalware (ai score=100)
VBA32Trojan.Wacatac
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_CLICKER.CVX
TencentWin32.Trojan.Bingoml.Ztjl
YandexTrojan.Malat!fTrJXs4QA1o
FortinetW32/Agent.MHO!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Win32/TrojanClicker.Delf.NKH?

Win32/TrojanClicker.Delf.NKH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment