Categories: Worm

Worm.DelfPMF.S22584676 removal instruction

The Worm.DelfPMF.S22584676 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DelfPMF.S22584676 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Worm.DelfPMF.S22584676?


File Info:

name: 1A46E6E944C20447979D.mlwpath: /opt/CAPEv2/storage/binaries/6473925693781ac01afabf4e38a6dd2f5382e4cdb638d2a6708ed1fb52f55539crc32: A51242ABmd5: 1a46e6e944c20447979d283a512666absha1: baad81ab61c57b2198aa4b2a19b17b83c2e8903csha256: 6473925693781ac01afabf4e38a6dd2f5382e4cdb638d2a6708ed1fb52f55539sha512: 500f96883a8698746c43a564c4f1a3a660e025453b734ca4055f1286fba9500f9ef3195dbea473d1c82649547cc5bcb3b0746fedb9a54d11ad007b54476a216assdeep: 24576:TrIZh5lrQpKN53X2vqMZ1fOt0i+V5GY/USVJFzQZme3a30RXQcwaO3c7j/QqMueO:T8H5tQpKN53X2vqMZ1fOt0i+V5GY/USotype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T107358D12B5D18FB1D4AF403085A997729677BC354F2097EB1384EE293F316C1AA39763sha3_384: 49acbc618a38ffcef97f65d29cf6c9323b888991373920a88190fa1f4f488a4c93638e05e1fc5f9d246c4fa49050785eep_bytes: 558bec83c4f0b838464000e874e2fffftimestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.DelfPMF.S22584676 also known as:

Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Agent.EICV
FireEye Generic.mg.1a46e6e944c20447
CAT-QuickHeal Worm.DelfPMF.S22584676
McAfee W32/HLLP.11042.gen
Cylance Unsafe
VIPRE BehavesLike.Win32.Malware.bsm (vs)
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 004bcce41 )
K7GW Trojan ( 004bcce41 )
Cybereason malicious.944c20
Baidu Win32.Virus.Lamer.f
Cyren W32/Aple.A.gen!Eldorado
Symantec W32.SillyP2P
ESET-NOD32 Win32/Delf.NAY
APEX Malicious
ClamAV Win.Malware.Delf-6737076-0
Kaspersky P2P-Worm.Win32.Delf.aj
BitDefender Trojan.Agent.EICV
NANO-Antivirus Trojan.Win32.Delf.oxkq
Avast Win32:Delf-SVI [Trj]
Tencent Virus.Win32.Lamer.fh
Ad-Aware Trojan.Agent.EICV
Sophos ML/PE-A
Comodo TrojWare.Win32.Pincav.AV@2rw0ny
DrWeb Win32.HLLW.Kazaa.924
Zillya Worm.Delf.Win32.3450
TrendMicro TROJ_AGENT_005911.TOMB
McAfee-GW-Edition BehavesLike.Win32.CoinMiner.th
Emsisoft Trojan.Agent.EICV (B)
SentinelOne Static AI – Malicious PE
GData Trojan.Agent.EICV
Jiangmin Worm/Delf.vm
Avira TR/Dropper.Gen
Antiy-AVL Trojan/Generic.ASVirus.2FE
Microsoft Worm:Win32/Xolxo.A
Cynet Malicious (score: 100)
AhnLab-V3 Worm/Win32.Delf.R119214
Acronis suspicious
BitDefenderTheta Gen:NN.ZelphiF.34062.dnZ@a0C2bxn
ALYac Trojan.Agent.EICV
MAX malware (ai score=88)
VBA32 BScope.Worm.Delf
Malwarebytes Malware.AI.3792586609
TrendMicro-HouseCall TROJ_AGENT_005911.TOMB
Rising Worm.P2p.Win32.Delf.bn (CLASSIC)
Yandex Trojan.GenAsa!HYSjiRN/8Mk
MaxSecure Virus.W32.Lamer.FG
Fortinet W32/Aple.A
AVG Win32:Delf-SVI [Trj]
Panda Trj/Genetic.gen
CrowdStrike win/malicious_confidence_100% (D)

How to remove Worm.DelfPMF.S22584676?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Malware.AI.1193900862 removal instruction

The Malware.AI.1193900862 is considered dangerous by lots of security experts. When this infection is active,…

9 mins ago

Malware.AI.1522466034 malicious file

The Malware.AI.1522466034 is considered dangerous by lots of security experts. When this infection is active,…

10 mins ago

How to remove “Fragtor.35742 (B)”?

The Fragtor.35742 (B) is considered dangerous by lots of security experts. When this infection is…

14 mins ago

Malware.AI.4082396169 malicious file

The Malware.AI.4082396169 is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

MSILHeracles.134289 malicious file

The MSILHeracles.134289 is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Malware.AI.3800365927 removal instruction

The Malware.AI.3800365927 is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago