Spy

Win32/Spy.Delf.PDD removal guide

Malware Removal

The Win32/Spy.Delf.PDD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.PDD virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Spy.Delf.PDD?


File Info:

name: E46B26E140ABB649B234.mlw
path: /opt/CAPEv2/storage/binaries/7d2fc9a45dae229203c5fbc7ac34603b5ad8d045c58c99c5829c909a8c859ce9
crc32: 4F6CCC6D
md5: e46b26e140abb649b234d21444c8215b
sha1: 090778244d1238aee55f08183be796e340c7d4a8
sha256: 7d2fc9a45dae229203c5fbc7ac34603b5ad8d045c58c99c5829c909a8c859ce9
sha512: ae7c6d5195d325b3b2b95bf4900c380eb2f14a1de601b9cd05a7cd5ad118a9cbe0ae45d385fb1b34619d55b80573eb999db68dfd2bfa3a12eb2af9ee3a066eaa
ssdeep: 6144:m+/i4jstG0Yp8VOxWlBLmaooahN0xQxZII6c2/v0G3NlM3uguwaeD8p4n4r5LwIC:O4js1Yp8sEBjPDfv0VuDeD8E41lMOU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1C48E36F5E08933C1275A3DDD1BA7A55829FE503E2858863BF81D4CCF39796382A193
sha3_384: c36c77aa04afdd3dc10053ae6a3e31579ac7c0f6dd556045841b5f8733ecdeb70b3fca55d2622a1dd626032500e62a18
ep_bytes: 558bec83c4f0b8b4674700e86cfbf8ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Delf.PDD also known as:

FireEyeGeneric.mg.e46b26e140abb649
McAfeeArtemis!E46B26E140AB
ZillyaTrojan.Genome.Win32.173271
K7AntiVirusSpyware ( 00461f721 )
K7GWSpyware ( 00461f721 )
Cybereasonmalicious.140abb
CyrenW32/Banload.L.gen!Eldorado
SymantecTrojan.Gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Delf.PDD
APEXMalicious
ClamAVWin.Trojan.7380389-1
TencentWin32.Trojan.Genome.dinb
ComodoMalware@#4dlwgcof1zth
TrendMicroTROJ_GEN.R03BC0PGT22
McAfee-GW-EditionGenericR-EKK!775CF8903681
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Mal/Banspy-K
JiangminTrojan/Genome.cett
WebrootW32.Trojan.Gen
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.5E
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32Trojan.Genome.af
TrendMicro-HouseCallTROJ_GEN.R03BC0PGT22
RisingTrojan.Generic@AI.83 (RDML:MYZ6uLTQ0nzm5MPEeKqr2w)
YandexTrojan.GenAsa!iS0GXipisjw
IkarusTrojan-Banker.Win32.Banker
FortinetW32/Banspy.K!tr.spy
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Spy.Delf.PDD?

Win32/Spy.Delf.PDD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment