Worm

Win32.Worm.Delf.NGA (file analysis)

Malware Removal

The Win32.Worm.Delf.NGA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Delf.NGA virus can do?

  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32.Worm.Delf.NGA?


File Info:

name: 9506349AB298A2BB25EC.mlw
path: /opt/CAPEv2/storage/binaries/d78235810f3eae0f34fb2d9dee51946c4dd717d35707c733897fd721f827ab04
crc32: 11A0C46C
md5: 9506349ab298a2bb25ecc7f0b30efc49
sha1: 0910a4a7d6822c0a5241ca1793649f80d8ae967a
sha256: d78235810f3eae0f34fb2d9dee51946c4dd717d35707c733897fd721f827ab04
sha512: 32b0b4aebdffca946492b0821840a71c52501b2145d5362d7638eec525c445f159d03a82e8195de9ff5b50ada16870c2ccde152061ff7f21f33df7a6d82c51a6
ssdeep: 12288:ONna5g6f6mPrRbgk1gZuDTFqeu4TROhxaC4CXj4xuzNpDj:2Af5Rbggt3FxuC60AXjZpH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCF48E22B2A14437D1732B78AC2B666D9C35BE113E28794B6BF51C4C4F3D39278292D7
sha3_384: 0583b7224ba967d3369fb8c43c560180337c2641bd58a27d78ed76e6eeafcd0a49e8528845282b9c790b67e22fc3668c
ep_bytes: 558bec83c4f0b8f41d4900e8a844f7ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32.Worm.Delf.NGA also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Delf.o!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.55571
MicroWorld-eScanWin32.Worm.Delf.NGA
McAfeeGeneric.boq
MalwarebytesMalware.Heuristic.1001
ZillyaWorm.Delf.Win32.2915
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaWorm:Win32/MalwareS.563fd805
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.ab298a
CyrenW32/Risk.UOOI-2840
ESET-NOD32Win32/Delf.NQC
APEXMalicious
BitDefenderWin32.Worm.Delf.NGA
NANO-AntivirusTrojan.Win32.Agent.damnf
AvastWin32:Banload-GIK [Trj]
EmsisoftWin32.Worm.Delf.NGA (B)
F-SecureTrojan.TR/Crypt.CFI.Gen
BaiduWin32.Worm.Delf.bd
VIPREWin32.Worm.Delf.NGA
TrendMicroTROJ_SCAR.EP
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.bh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9506349ab298a2bb
SophosMal/Generic-D
GDataWin32.Worm.Delf.NGA
GoogleDetected
AviraTR/Crypt.CFI.Gen
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.Delf
ArcabitWin32.Worm.Delf.NGA
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
ALYacWin32.Worm.Delf.NGA
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SCAR.EP
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
YandexWorm.Delf!6mz6BdPnyno
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.NQC!worm
AVGWin32:Banload-GIK [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32.Worm.Delf.NGA?

Win32.Worm.Delf.NGA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment