Worm

Worm.DelfPMF.S30896276 removal instruction

Malware Removal

The Worm.DelfPMF.S30896276 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DelfPMF.S30896276 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.DelfPMF.S30896276?


File Info:

name: BF6A378D0026A8218AA4.mlw
path: /opt/CAPEv2/storage/binaries/a833189fc74534df300a8fd3fb94259708a0e91a598ed1adef92a1baedd9d2b5
crc32: F1F0AE0D
md5: bf6a378d0026a8218aa44b6fa0ffb8cc
sha1: d83993928db01c43ddb4b9216a910cead17d0237
sha256: a833189fc74534df300a8fd3fb94259708a0e91a598ed1adef92a1baedd9d2b5
sha512: 67116b383b4db109c7bfb8f9bd50c528105444123426b1f52a6587f15da90ecf15c9555a247d07d6bdb59acfd8d32ef45450917240703c358713ab58bff62b40
ssdeep: 49152:hhNAiorWg8zIqvU9+I4O9+I4HgjI45TMwwapIgTTpYqBbM5gX:FLhjU0O0hLapIg6OGgX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B365B26F1B04565C066C075CF829726EBB13C558BF087EB6245B3E92F33AD0B939726
sha3_384: 2bdbb2436037cae94b394a0b4d8a05ebc09b20e9a33666b4e3fd56805951824cf57662e278a372abba70236e2b4847d4
ep_bytes: 558bec83c4f0b838464000e874e2ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.DelfPMF.S30896276 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.EICV
FireEyeGeneric.mg.bf6a378d0026a821
CAT-QuickHealWorm.DelfPMF.S30896276
SkyhighBehavesLike.Win32.HLLP.rh
McAfeeW32/HLLP.11042.gen
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Delf.Win32.3450
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.28db01
BaiduWin32.Virus.Lamer.f
SymantecW32.SillyP2P
tehtrisGeneric.Malware
ESET-NOD32Win32/Delf.NAY
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Delf.aj
BitDefenderTrojan.Agent.EICV
NANO-AntivirusTrojan.Win32.Delf.oxkq
AvastWin32:Delf-SVI [Trj]
TencentVirus.Win32.Lamer.fh
EmsisoftTrojan.Agent.EICV (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Kazaa.924
VIPRETrojan.Agent.EICV
TrendMicroTROJ_AGENT_005911.TOMB
SophosW32/BagarBu-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10YRRCT
JiangminWorm/Delf.vm
WebrootW32.Worm.Gen
VaristW32/Aple.A.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLVirus/Win32.BagarBubba.a
Kingsoftmalware.kb.b.959
XcitiumTrojWare.Win32.Pincav.AV@2rw0ny
ArcabitTrojan.Agent.EICV
ZoneAlarmP2P-Worm.Win32.Delf.aj
MicrosoftWorm:Win32/Xolxo.A
GoogleDetected
AhnLab-V3Worm/Win32.Delf.R119214
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.36680.@pZ@a0C2bxn
ALYacTrojan.Agent.EICV
VBA32Worm.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_005911.TOMB
RisingWorm.P2p.Win32.Delf.bn (CLASSIC)
YandexTrojan.GenAsa!HYSjiRN/8Mk
IkarusTrojan.Agent
MaxSecureVirus.W32.Lamer.FG
FortinetW32/Aple.A
AVGWin32:Delf-SVI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.DelfPMF.S30896276?

Worm.DelfPMF.S30896276 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment