Published Jan 16, 2007 | Updated Sep 15, 2017


Severe |Detected with Windows Defender Antivirus

Aliases: Win32/Afrootix (CA) Trojan.Win32.Madtol.a (Kaspersky) W32/Maddis.worm (McAfee) W32/Madtol.A (Norman) Troj/Madtol-A (Sophos) Backdoor.IRC.Ratsou.B (Symantec) TROJ_MADTOL.A (Trend Micro)


Trojan:Win32/Delf.M is a user-mode rootkit that hides its own presence on the system, as well as hiding the presence of other malicious software to which it may be associated. This trojan will be detected by Microsoft as Trojan:Win32/Delf.M!CME-96.
Attempting manual removal of Trojan:Win32/Delf.M is not recommended. To detect and remove this trojan, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner ( For more information, visit
Follow us