Worm

Worm:Win32/Delf.AY removal guide

Malware Removal

The Worm:Win32/Delf.AY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Delf.AY virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Delf.AY?


File Info:

name: E54E4792830C0A12DAE2.mlw
path: /opt/CAPEv2/storage/binaries/448aebacf0b587c3cf0c93b2fc5248f2a7ab15434a8d0fe6567cc82e2f6b1582
crc32: CA387952
md5: e54e4792830c0a12dae225a542b9f12e
sha1: 03cecdee0d1d7acd69136158c9e08b7789525d38
sha256: 448aebacf0b587c3cf0c93b2fc5248f2a7ab15434a8d0fe6567cc82e2f6b1582
sha512: fa65c3de4595c3fbd5171412aacc6b0ee1f3697942218dc39156c95cf5b8192818d1dd972e144ffea2136b5e35d525e29c8a402446fd2e8cef64b4672f893926
ssdeep: 12288:g8L25c+ugtP0AF9jh0zzF9zl04skRICpwPz/0wi6AoCPY1urkh//spebIl6nMfS3:gGr+hiAF9gR0aPpC/FAoCPY1urkh//sY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1F47D23B1A3C437D17217385C7B97A6B47B7B353A244943B7E41F4C1BB8A8168292DB
sha3_384: 71bf5424372040c7c38fb5309493a2619393ff23bff04b6a2870f601309dbc2f0ea1452b8aa975d2312718222b94af98
ep_bytes: eb1066623a432b2b484f4f4b90e99820
timestamp: 2005-11-03 10:59:42

Version Info:

0: [No Data]

Worm:Win32/Delf.AY also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Diss.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.58171
MicroWorld-eScanGen:Trojan.AV-Killer.TGW@aSGDn4gc
FireEyeGeneric.mg.e54e4792830c0a12
SkyhighBehavesLike.Win32.Injector.bh
McAfeeArtemis!E54E4792830C
Cylanceunsafe
VIPREGen:Trojan.AV-Killer.TGW@aSGDn4gc
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0005714b1 )
BitDefenderGen:Trojan.AV-Killer.TGW@aSGDn4gc
K7GWEmailWorm ( 0005714b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.3F00959A21
VirITI-WORM.Win32.Small.C
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Delf.NBC
APEXMalicious
ClamAVWin.Worm.Small-13877
KasperskyTrojan.Win32.Diss.susrc
AlibabaWorm:Win32/SmallWorm.913f2e13
NANO-AntivirusTrojan.Win32.Small.ttxbx
RisingBackdoor.Agent!1.663A (CLASSIC)
EmsisoftGen:Trojan.AV-Killer.TGW@aSGDn4gc (B)
GoogleDetected
F-SecureWorm.WORM/Delf.AA.43
BaiduWin32.Worm-P2P.Agent.d
ZillyaWorm.Delf.Win32.135
TrendMicroTROJ_FAM_00011e3.TOMA
Trapminesuspicious.low.ml.score
SentinelOneStatic AI – Suspicious PE
JiangminWorm/Small.ae
WebrootW32.Worm.Gen
VaristW32/SmallWorm.A.gen!Eldorado
AviraWORM/Delf.AA.43
MAXmalware (ai score=100)
Antiy-AVLWorm[P2P]/Win32.Cosmu.a
KingsoftWin32.Trojan.Diss.susrc
MicrosoftWorm:Win32/Delf.AY
XcitiumEmailWorm.Win32.Small.C@4mrrmw
ArcabitTrojan.AV-Killer.ED172AA
ZoneAlarmTrojan.Win32.Diss.susrc
GDataGen:Trojan.AV-Killer.TGW@aSGDn4gc
CynetMalicious (score: 99)
AhnLab-V3Worm/Win.Small.R510009
ALYacGen:Trojan.AV-Killer.TGW@aSGDn4gc
DeepInstinctMALICIOUS
VBA32Trojan.Diss
MalwarebytesMalware.AI.4150979424
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FAM_00011e3.TOMA
TencentWorm.Win32.Spybot.b
YandexTrojan.GenAsa!sQK1kAES604
IkarusEmail-Worm.Win32.Small
MaxSecureTrojan.Malware.73477801.susgen
FortinetW32/Delf.NBC@mm
AVGWin32:Small-CSG [Wrm]
Cybereasonmalicious.e0d1d7
AvastWin32:Small-CSG [Wrm]

How to remove Worm:Win32/Delf.AY?

Worm:Win32/Delf.AY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment