Worm

What is “Worm.DelfPMF.S30896276”?

Malware Removal

The Worm.DelfPMF.S30896276 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DelfPMF.S30896276 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools

How to determine Worm.DelfPMF.S30896276?


File Info:

name: 3FB9F37E875F6B7E4DBB.mlw
path: /opt/CAPEv2/storage/binaries/34ee4c874a6159b76509adeb3d801b97f4f4cde1d12f065c0c733844704adf88
crc32: 35CB8768
md5: 3fb9f37e875f6b7e4dbbf05968b0307a
sha1: 61f1099fe1bce276c4f026a7b0d4daaa53b4c60b
sha256: 34ee4c874a6159b76509adeb3d801b97f4f4cde1d12f065c0c733844704adf88
sha512: 7cae64b0aabffec5b625ef00b380998c8329eb34a5f99ed2a8cae9b18e7c86a36e469d0ced7818a92d2f77e6aae968826c5dfb11e4246c714bd50d679a2ccdaa
ssdeep: 12288:rAce6EbNidvL/JM7aIrVQrE1SpYQqLWpc0qpb0qD0xcHfN:rXuIlMnUE1SpYJLMq2qDF/N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE956386F643ED4BE3C5E8348825DA76626237BE97F34879BC6CB5D8F61A1533014E02
sha3_384: 73a8c712168516f808b85a5cc440a3457ca6b51420c565d37e45e9be55906bb5c9456c7f4db312c72376f37578695ec8
ep_bytes: 558bec83c4f0b838464000e874e2ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.DelfPMF.S30896276 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.EICV
ClamAVWin.Virus.Wapomi-9623880-0
CAT-QuickHealWorm.DelfPMF.S30896276
SkyhighBehavesLike.Win32.HLLP.tm
ALYacTrojan.Agent.EICV
MalwarebytesGeneric.Trojan.Delf.DDS
VIPRETrojan.Agent.EICV
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053c5661 )
K7GWTrojan ( 0053c5661 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Agent.EICV
BaiduWin32.Virus.Lamer.f
SymantecW32.SillyP2P
Elasticmalicious (high confidence)
ESET-NOD32Win32/Delf.NAY
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Delf.aj
BitDefenderTrojan.Agent.EICV
NANO-AntivirusTrojan.Win32.Delf.oxkq
AvastWin32:Delf-SVI [Trj]
RisingWorm.P2p.Win32.Delf.bn (CLASSIC)
EmsisoftTrojan.Agent.EICV (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Kazaa.924
ZillyaWorm.Delf.Win32.3450
TrendMicroTROJ_AGENT_005911.TOMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3fb9f37e875f6b7e
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminWorm/Delf.vm
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLVirus/Win32.BagarBubba.a
XcitiumTrojWare.Win32.Pincav.AV@2rw0ny
MicrosoftWorm:Win32/Xolxo.A
ZoneAlarmP2P-Worm.Win32.Delf.aj
GDataWin32.Trojan.PSE.10YRRCT
VaristW32/Delf.QB.gen!Eldorado
AhnLab-V3Worm/Win32.Delf.R119214
Acronissuspicious
McAfeeW32/HLLP.11042.gen
VBA32Worm.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_005911.TOMB
TencentVirus.Win32.Lamer.fh
YandexTrojan.GenAsa!HYSjiRN/8Mk
IkarusWorm.Win32.Eggnog
MaxSecureVirus.W32.Lamer.FG
FortinetW32/Aple.A
BitDefenderThetaGen:NN.ZelphiF.36680.9nZ@auciUnn
AVGWin32:Delf-SVI [Trj]
Cybereasonmalicious.fe1bce
DeepInstinctMALICIOUS

How to remove Worm.DelfPMF.S30896276?

Worm.DelfPMF.S30896276 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment