Spy Trojan

Trojan.Spy.Delf.NMJ removal tips

Malware Removal

The Trojan.Spy.Delf.NMJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Delf.NMJ virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Spy.Delf.NMJ?


File Info:

name: 631C414EA82D92ECC6CF.mlw
path: /opt/CAPEv2/storage/binaries/c089ee105f852d404941dd54647a575b7ecbeac550fff52ff882ea6f4b908302
crc32: 382148B9
md5: 631c414ea82d92ecc6cf854b7cd95c3a
sha1: 12644c0ccbdd2be738ed8d89a5751e5b16de9819
sha256: c089ee105f852d404941dd54647a575b7ecbeac550fff52ff882ea6f4b908302
sha512: 680c5e2671395aa91fb097dc2985f6b721be19dca603c3e05039491b05db91713dc9d17e63f9f86495d11c64d5470a461b63fc2e5a356c943677293f789cfa49
ssdeep: 6144:JGNuZ9P4IawJd+fNiP7wdD7XdrBeEa9A:JTwjw6fNisdD7XT7a9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F23413A369236C42F35809F5E5CB86613B24AB494FAF5F12F1B37E9F29613190BD061C
sha3_384: f07797ec3fcf204d524401158a1259890a54b66f6052e4a69b3ebb4547538bb10009573a6b7c3763c9859a1e97dd76be
ep_bytes: 60be000047008dbe0010f9ffc787c480
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Spy.Delf.NMJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Delf.l!c
CynetMalicious (score: 99)
CMCGeneric.Win32.631c414ea8!MD
McAfeeArtemis!631C414EA82D
CylanceUnsafe
ZillyaTrojan.Delf.Win32.47437
SangforTrojan.Win32.Delf.bqq
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/BScope.43662907
K7GWTrojan ( 0055e3e61 )
K7AntiVirusTrojan ( 0055e3e61 )
CyrenW32/Trojan.VAYH-4493
ESET-NOD32a variant of Generik.LYKHYWE
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Delf.bqq
BitDefenderTrojan.Spy.Delf.NMJ
NANO-AntivirusTrojan.Win32.Delf.oikf
ViRobotTrojan.Win32.A.Delf.252416.C[UPX]
MicroWorld-eScanTrojan.Spy.Delf.NMJ
AvastFileRepMalware
TencentWin32.Trojan-spy.Delf.Wlfo
Ad-AwareTrojan.Spy.Delf.NMJ
EmsisoftTrojan.Spy.Delf.NMJ (B)
DrWebTrojan.DownLoader.64831
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGU21
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.631c414ea82d92ec
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.Delf
GDataTrojan.Spy.Delf.NMJ
JiangminTrojanSpy.Delf.bpw
WebrootW32.Downloader.Gen
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1853D14
KingsoftWin32.Troj.Delf.b.(kcloud)
ArcabitTrojan.Spy.Delf.NMJ
MicrosoftPWS:Win32/Zbot!ml
AhnLab-V3Trojan/Win32.Xema.R137554
BitDefenderThetaGen:NN.ZelphiF.34062.pmGfaqYEVaq
ALYacTrojan.Spy.Delf.NMJ
MAXmalware (ai score=99)
VBA32BScope.Trojan.AntiAV
TrendMicro-HouseCallTROJ_GEN.R002C0PGU21
YandexTrojan.Malagent!mrF3G6pLba8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.729596.susgen
FortinetMalware_fam.gw
AVGFileRepMalware
Cybereasonmalicious.ea82d9
PandaTrj/CI.A

How to remove Trojan.Spy.Delf.NMJ?

Trojan.Spy.Delf.NMJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment