Spy

About “Win32/Spy.Delf.OZI” infection

Malware Removal

The Win32/Spy.Delf.OZI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.OZI virus can do?

  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Spy.Delf.OZI?


File Info:

name: DE33BA8D9F8398956EA5.mlw
path: /opt/CAPEv2/storage/binaries/82fa69368f36375085f3c82853b65ad4c903f842e82fa2a3f846717882d28fbd
crc32: 10B3671F
md5: de33ba8d9f8398956ea598d48a1da730
sha1: 4518a6bd2b00355f6fe215e879ab058b98cd8923
sha256: 82fa69368f36375085f3c82853b65ad4c903f842e82fa2a3f846717882d28fbd
sha512: d19d803e0b2a18f746811f8cfc1a0cdea3b42d333adff3f285ffa19dcbd262db965fa487907a563dfd782b87af9fe2c024461d52178f0863cea74aae73ec0270
ssdeep: 12288:ZclMU2NLw0kOk0YBg2DjMO2qYNSQd8LZs4ixsiNhkApRariGgEC:a3z9Ok0nAeLNDw1ifNhQiGgE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4F4BF32F6915477C1736A389C1B93A99829BF203DBCA8467BF51D4C4F3A6913C292D3
sha3_384: da8f145e21b0aee7b3e913ceb19806faff8e3c4929f9347ab8ce0385637fff4d4731d4fa3155fa34bc2c78dd74ecb9de
ep_bytes: 558bec83c4f0b8649f4700e8dcc6f8ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Adobe TM
FileDescription: Adobe reader
FileVersion: 1.0.0.0
InternalName: Adobe reader
LegalCopyright: Adobe TM Co.Ltd
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0409 0x04e4

Win32/Spy.Delf.OZI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tapazom.4!c
MicroWorld-eScanGen:Heur.Mint.Zard.1
FireEyeGeneric.mg.de33ba8d9f839895
CAT-QuickHealW32.Virut.G
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaBackdoor:Win32/Tapazom.afe28190
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.201D908C19
VirITTrojan.Win32.Generic.HGA
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Delf.OZI
APEXMalicious
ClamAVWin.Trojan.Generickd-182
BitDefenderGen:Heur.Mint.Zard.1
NANO-AntivirusTrojan.Win32.Strictor.bfqzfq
TrendMicroTROJ_TAPAZOM.A
Trapminesuspicious.low.ml.score
IkarusTrojan.Win32.Agent
AviraTR/Spy.Agent.yknqq
MAXmalware (ai score=100)
KingsoftWin32.Virut.nf.53248
XcitiumMalware@#2qfifc7de6wtm
ArcabitTrojan.Mint.Zard.1
ViRobotTrojan.Win32.S.Agent.749568.H
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Dapato.R49251
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_TAPAZOM.A
TencentMalware.Win32.Gencirc.10bde7af
YandexTrojan.GenAsa!ecm7pw0NXvI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Trojandldr.OZI!tr
Cybereasonmalicious.d9f839
alibabacloudTrojan

How to remove Win32/Spy.Delf.OZI?

Win32/Spy.Delf.OZI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment