Worm

Worm.DelfPMF.S30896276 (file analysis)

Malware Removal

The Worm.DelfPMF.S30896276 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DelfPMF.S30896276 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.DelfPMF.S30896276?


File Info:

name: C86FCF1E72BFE83A4DF5.mlw
path: /opt/CAPEv2/storage/binaries/7c24d9095590cae02e5bd3a34cca5b91dc70ea6ca371e83c174bb8bb380c50f7
crc32: 777EB573
md5: c86fcf1e72bfe83a4df59fe7cd9d3ba4
sha1: 60bd79e7edf797acb3fb4129a9cdb544376b773c
sha256: 7c24d9095590cae02e5bd3a34cca5b91dc70ea6ca371e83c174bb8bb380c50f7
sha512: 2a57e231b45989daf6fc65c559a3e7af2a86d07241bb5b5d5ff621fbb19338bf02277b76a5ae552605aae0fc3addd70ce14395b9b7981827122ae2f281c6f0f0
ssdeep: 49152:vT/qJtb2Ikljd7UL85jg9WUJ+Cq99LyHHI+t6O8N+ailEy6dmpzeioK2enVzG1nh:vbz7+85Ok0oAaldmdmnpaU0F03
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5566B12F6B48276D073C075CE829665EB323C494BF055DB2285B7EC2E37AD1B63A721
sha3_384: a9bb47622e5a6c0115442c34c2cdcaf8700f86c03c87e71c7d9d20d8a1c1058b359f72a93576a5b0eb342de17dc0c698
ep_bytes: 558bec83c4f0b838464000e874e2ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.DelfPMF.S30896276 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.EICV
ClamAVWin.Ransomware.Azvo-9979243-0
CAT-QuickHealWorm.DelfPMF.S30896276
SkyhighBehavesLike.Win32.HLLP.th
ALYacTrojan.Agent.EICV
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Delf.Win32.3450
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Agent.EICV
BitDefenderThetaGen:NN.ZelphiF.36792.@pZ@a0C2bxn
SymantecW32.SillyP2P
tehtrisGeneric.Malware
ESET-NOD32Win32/Delf.NAY
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Delf.aj
BitDefenderTrojan.Agent.EICV
NANO-AntivirusTrojan.Win32.Delf.oxkq
AvastWin32:Delf-SVI [Trj]
TencentVirus.Win32.Lamer.fh
SophosW32/BagarBu-A
BaiduWin32.Virus.Lamer.f
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Kazaa.924
VIPRETrojan.Agent.EICV
TrendMicroTROJ_AGENT_005911.TOMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c86fcf1e72bfe83a
EmsisoftTrojan.Agent.EICV (B)
IkarusWorm.Win32.Eggnog
JiangminWorm/Delf.vm
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLVirus/Win32.BagarBubba.a
Kingsoftmalware.kb.b.789
XcitiumTrojWare.Win32.Pincav.AV@2rw0ny
MicrosoftWorm:Win32/Xolxo.A
ZoneAlarmP2P-Worm.Win32.Delf.aj
GDataTrojan.Agent.EICV
VaristW32/Aple.A.gen!Eldorado
AhnLab-V3Worm/Win32.Delf.R119214
Acronissuspicious
McAfeeW32/HLLP.11042.gen
VBA32Worm.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_005911.TOMB
RisingWorm.P2p.Win32.Delf.bn (CLASSIC)
YandexTrojan.GenAsa!HYSjiRN/8Mk
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Lamer.FG
FortinetW32/Aple.A
AVGWin32:Delf-SVI [Trj]
Cybereasonmalicious.7edf79
DeepInstinctMALICIOUS

How to remove Worm.DelfPMF.S30896276?

Worm.DelfPMF.S30896276 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment