Malware

Win32:Delf-QTB [Trj] removal

Malware Removal

The Win32:Delf-QTB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Delf-QTB [Trj] virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32:Delf-QTB [Trj]?


File Info:

crc32: AE153E8D
md5: ff62b1056de03eadc8ad605d410569b7
name: FF62B1056DE03EADC8AD605D410569B7.mlw
sha1: 3f93845b173f728e5558de813ac56cf22bc95491
sha256: c74dcecb4c30804e3aed285625c8920d88375a7cfd7bf1fcbaab8c5ce725aecc
sha512: 43e6bf36eb337a9b6fb9256a638ad11e766d939294ceabc08fe5d11f8abd12b154a188fa9716cdeb226bc580f39945f329d1a6230c9eb14d45f20d4beab1d09a
ssdeep: 1536:lNI6DnMCLosDz1OwVIBaVlKs24mD+dL9I4bU9hSHIJTx9Sp9xVZjro:XI6NLZ1OLNDWpI2U9koJT6pjVZXo
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32:Delf-QTB [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f6e981 )
LionicTrojan.Win32.Generic.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.11464
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Amnesia.B
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5222
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Filecoder.45b5bde2
K7GWTrojan ( 004f6e981 )
Cybereasonmalicious.56de03
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Delf-QTB [Trj]
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderTrojan.Ransom.Amnesia.B
NANO-AntivirusTrojan.Win32.Filecoder.eokqut
MicroWorld-eScanTrojan.Ransom.Amnesia.B
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Ransom.Amnesia.B
SophosMal/Generic-S
ComodoMalware@#xzddd1excyzq
BitDefenderThetaAI:Packer.6826D7AF1F
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_PURGE.F117EC
McAfee-GW-EditionBehavesLike.Win32.Mytob.nc
FireEyeGeneric.mg.ff62b1056de03ead
EmsisoftTrojan.Ransom.Amnesia.B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.aydyq
WebrootW32.Ransom.Gen
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1FF6E3D
MicrosoftWorm:Win32/Skeeyah.A!rfn
ArcabitTrojan.Ransom.Amnesia.B
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataTrojan.Ransom.Amnesia.B
AhnLab-V3Trojan/Win32.CryptXXX.R208829
McAfeeArtemis!FF62B1056DE0
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Kitoles
PandaTrj/Ransom.M
TrendMicro-HouseCallRansom_PURGE.F117EC
YandexTrojan.GenAsa!naaCZ9xMLiA
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr
AVGWin32:Delf-QTB [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Amnesia.HwsBEpsA

How to remove Win32:Delf-QTB [Trj]?

Win32:Delf-QTB [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment