Spy

Win32/Spy.Delf.PAQ malicious file

Malware Removal

The Win32/Spy.Delf.PAQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.PAQ virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering

How to determine Win32/Spy.Delf.PAQ?


File Info:

name: CCC08330C1F81BADF780.mlw
path: /opt/CAPEv2/storage/binaries/916f0d296c002322e10adee603c760416b3b10448b08a16368d9422628f6526a
crc32: D2E19AC8
md5: ccc08330c1f81badf7808b4a8a6b3559
sha1: 4cb09196d6699830dd5057cd5edbef9671cb2f82
sha256: 916f0d296c002322e10adee603c760416b3b10448b08a16368d9422628f6526a
sha512: cf1a19797534149819a7cfe8aa24e9727825b8cada345f73c889e49b3c541e888e7afdc0aed4fefa2f98826559cf531eae1674a16a2cf8c2b7ea5ab0988e9542
ssdeep: 6144:SUeksghM9cLpHpDlTqp0x6rvGwDaYiuBkhEzak1M4oSO:8H+M9cLpHlP6rvGU5iPCp1M4oSO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C54E012A3F80558F9F65F34ADBA4AA00E37BC59B976CE6E1610784E2C71E80DD61733
sha3_384: 3eda39adb2e3db170875795c0e18cc84290a43ff955352ec41e973b1323dbf99ea1f033d49ead4874a8ebc769b1ffe40
ep_bytes: 60be002048008dbe00f0f7ffc787a8a0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Delf.PAQ also known as:

CyrenCloudW32/Trojan.XVKR-8284:105:50:100.916F0D29!Threatlookup
BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.Click2.14861
CynetMalicious (score: 100)
FireEyeGeneric.mg.ccc08330c1f81bad
SkyhighBehavesLike.Win32.Dropper.dc
McAfeeArtemis!CCC08330C1F8
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Genome.Win32.153615
SangforTrojan.Win32.Orsam.rts
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.6d6699
VirITTrojan.Win32.Banker6.PVQ
ESET-NOD32a variant of Win32/Spy.Delf.PAQ
AlibabaTrojanSpy:Win32/Banker.f2d1a9f0
NANO-AntivirusTrojan.Win32.Clicker.edcinh
EmsisoftGen:Variant.Jaik.167904 (B)
F-SecureTrojan.TR/Downloader.Gen
VIPREGen:Variant.Jaik.167904
TrendMicroTSPY_BANKER.RHV
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.Banker.JU
JiangminTrojan/Genome.bkpy
WebrootW32.Malware.Gen
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Unknown.a
XcitiumMalware@#2839szfeubc1e
ArcabitTrojan.Jaik.D28FE0
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Orsam!rts
GoogleDetected
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Jaik.167904
DeepInstinctMALICIOUS
Cylanceunsafe
TencentWin32.Trojan.Downloader.Bkjl
YandexTrojan.GenAsa!YTLJ1rvWIlY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1380222.susgen
FortinetBanker.HB3!tr.pws
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Spy.Delf.PAQ?

Win32/Spy.Delf.PAQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment