Worm

Worm.DelfPMF.S22584676 removal instruction

Malware Removal

The Worm.DelfPMF.S22584676 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DelfPMF.S22584676 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Worm.DelfPMF.S22584676?


File Info:

name: 1A46E6E944C20447979D.mlw
path: /opt/CAPEv2/storage/binaries/6473925693781ac01afabf4e38a6dd2f5382e4cdb638d2a6708ed1fb52f55539
crc32: A51242AB
md5: 1a46e6e944c20447979d283a512666ab
sha1: baad81ab61c57b2198aa4b2a19b17b83c2e8903c
sha256: 6473925693781ac01afabf4e38a6dd2f5382e4cdb638d2a6708ed1fb52f55539
sha512: 500f96883a8698746c43a564c4f1a3a660e025453b734ca4055f1286fba9500f9ef3195dbea473d1c82649547cc5bcb3b0746fedb9a54d11ad007b54476a216a
ssdeep: 24576:TrIZh5lrQpKN53X2vqMZ1fOt0i+V5GY/USVJFzQZme3a30RXQcwaO3c7j/QqMueO:T8H5tQpKN53X2vqMZ1fOt0i+V5GY/USo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107358D12B5D18FB1D4AF403085A997729677BC354F2097EB1384EE293F316C1AA39763
sha3_384: 49acbc618a38ffcef97f65d29cf6c9323b888991373920a88190fa1f4f488a4c93638e05e1fc5f9d246c4fa49050785e
ep_bytes: 558bec83c4f0b838464000e874e2ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.DelfPMF.S22584676 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EICV
FireEyeGeneric.mg.1a46e6e944c20447
CAT-QuickHealWorm.DelfPMF.S22584676
McAfeeW32/HLLP.11042.gen
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.bsm (vs)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.944c20
BaiduWin32.Virus.Lamer.f
CyrenW32/Aple.A.gen!Eldorado
SymantecW32.SillyP2P
ESET-NOD32Win32/Delf.NAY
APEXMalicious
ClamAVWin.Malware.Delf-6737076-0
KasperskyP2P-Worm.Win32.Delf.aj
BitDefenderTrojan.Agent.EICV
NANO-AntivirusTrojan.Win32.Delf.oxkq
AvastWin32:Delf-SVI [Trj]
TencentVirus.Win32.Lamer.fh
Ad-AwareTrojan.Agent.EICV
SophosML/PE-A
ComodoTrojWare.Win32.Pincav.AV@2rw0ny
DrWebWin32.HLLW.Kazaa.924
ZillyaWorm.Delf.Win32.3450
TrendMicroTROJ_AGENT_005911.TOMB
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.th
EmsisoftTrojan.Agent.EICV (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.EICV
JiangminWorm/Delf.vm
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASVirus.2FE
MicrosoftWorm:Win32/Xolxo.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Delf.R119214
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34062.dnZ@a0C2bxn
ALYacTrojan.Agent.EICV
MAXmalware (ai score=88)
VBA32BScope.Worm.Delf
MalwarebytesMalware.AI.3792586609
TrendMicro-HouseCallTROJ_AGENT_005911.TOMB
RisingWorm.P2p.Win32.Delf.bn (CLASSIC)
YandexTrojan.GenAsa!HYSjiRN/8Mk
MaxSecureVirus.W32.Lamer.FG
FortinetW32/Aple.A
AVGWin32:Delf-SVI [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.DelfPMF.S22584676?

Worm.DelfPMF.S22584676 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment