Spy

Win32/Spy.Delf.OZJ removal tips

Malware Removal

The Win32/Spy.Delf.OZJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.OZJ virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
dominiocapodeicapi.zapto.org

How to determine Win32/Spy.Delf.OZJ?


File Info:

crc32: 9E37F9BD
md5: 859df3585568f146d4c890b80a780e9a
name: 859DF3585568F146D4C890B80A780E9A.mlw
sha1: 60ec965ae862676d8115cb34420218493702dc9a
sha256: d3b583610e0cc7e7b374ee9f7bb71885ad37a4260267192e1575cf8dca74a828
sha512: 2889bc48a886b7e0ec7615f41fd43bb02a5214ca5c77c0f638cca25e7da5c0b7f4ba7d8139cba482ff8d4242ddc3a06e6ea8121eced722d5e89d009bbc4f89ce
ssdeep: 24576:knNx08HP5wvm64nTqkVVpYMPxgixFhzyh:kng25Mm64Td/pBPnh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Spy.Delf.OZJ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.9477
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Dynamer.A4
ALYacGen:Variant.Zusy.363733
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.45465
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/starter.ali1000030
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.85568f
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Delf.OZJ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Jacard-6896729-0
KasperskyTrojan-Ransom.Win32.Blocker.spp
BitDefenderGen:Variant.Zusy.363733
NANO-AntivirusTrojan.Win32.Blocker.cufngw
ViRobotTrojan.Win32.A.Blocker.1206272
MicroWorld-eScanGen:Variant.Zusy.363733
TencentTrojan-ransom.Win32.Blocker.kjb
Ad-AwareGen:Variant.Zusy.363733
SophosMal/Generic-S
BitDefenderThetaAI:Packer.68042D5919
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.859df3585568f146
EmsisoftGen:Variant.Zusy.363733 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.acs
AviraHEUR/AGEN.1126519
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.96C18
MicrosoftTrojanSpy:Win32/Ursnif
GDataGen:Variant.Zusy.363733
AhnLab-V3Trojan/Win32.Blocker.R67151
McAfeeGenericR-FTQ!859DF3585568
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.3963636539
RisingTrojan.Injector!1.BB2B (CLASSIC)
YandexTrojan.GenAsa!a5DpXfnoP88
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dropper.XUQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Spy.Delf.OZJ?

Win32/Spy.Delf.OZJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment