Malware

Should I remove “Win32:Delf-BTU [Wrm]”?

Malware Removal

The Win32:Delf-BTU [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Delf-BTU [Wrm] virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32:Delf-BTU [Wrm]?


File Info:

name: 14889A540484C66E0E73.mlw
path: /opt/CAPEv2/storage/binaries/987b180ca0a83808be938bd6fbebdcd0d4cd1fa526d1a56357f3eacb27de1212
crc32: 3B37CA50
md5: 14889a540484c66e0e739a0bd3ccde60
sha1: bc5f21f7c164f8c907a95f45eff4b1d4e4f6ea15
sha256: 987b180ca0a83808be938bd6fbebdcd0d4cd1fa526d1a56357f3eacb27de1212
sha512: c52965f3aca0751970de2202cb0d007618511651b27a558e892da70903d7238a7fdefd435efa89cbde8148edfdf24078cf0ef8dfea2f280c65b2d5dcf1fb90e6
ssdeep: 3072:7Zc9t6RoYuMuYeIAZlL9IqTTeTTTfqTTTJTTTTTnTTTTTThqTTTTTTfLTTTTTTTx:+ZCAZglxCzn76ppggmhOF0HFZlxI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAB47CBAB6A098B7D05709390C46E238B37CFE317B228613B7997B0E1F752514C4B1E6
sha3_384: d1099d784f4ce50e553ba411c899de7bf776b1d99eb61d8ed281869af64b07705fffc1dbd46e9384715e7ee1942a0cf1
ep_bytes: 558bec83c4f4b858e94000e8c06fffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Delf-BTU [Wrm] also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Delf.tpC4
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent
ClamAVWin.Malware.Delf-9941391-0
FireEyeTrojan.Agent
McAfeeW32/Android
Cylanceunsafe
VIPRETrojan.Agent
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 0008d5951 )
AlibabaWorm:Win32/Soltern.9cdd
K7GWVirus ( 0008d5951 )
Cybereasonmalicious.40484c
VirITWin32.SN1995K.A
CyrenW32/Delf.QSVZ-6376
SymantecW32.Sinau
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Delf.q
BitDefenderTrojan.Agent
AvastWin32:Delf-BTU [Wrm]
TencentVirus.Win32.Delf.qa
TACHYONWorm/W32.DP-Agent.Zen
EmsisoftTrojan.Agent (B)
DrWebWin32.HLLP.SN1995K
ZillyaVirus.Delf.Win32.26
McAfee-GW-EditionBehavesLike.Win32.Android.hz
SophosW32/Sinau-A
IkarusVirus.Win32.Delf.q
GDataTrojan.Agent
JiangminTrojan/Delf.tni
Antiy-AVLVirus/Win32.Delf.q
XcitiumWin32.Delf.Q@14o6
ArcabitTrojan.Agent
ZoneAlarmVirus.Win32.Delf.q
MicrosoftVirus:Win32/Andriod.B
GoogleDetected
AhnLab-V3Win32/Delf.Q.X1343
Acronissuspicious
ALYacTrojan.Agent
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Suspicious
RisingVirus.Delf!8.774 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.win32.delf.q
FortinetW32/Sinau.A1TR
AVGWin32:Delf-BTU [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:Delf-BTU [Wrm]?

Win32:Delf-BTU [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment