Spy

Win32/Spy.Delf.PLU removal guide

Malware Removal

The Win32/Spy.Delf.PLU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.PLU virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Spy.Delf.PLU?


File Info:

name: A5FB49045C1360860536.mlw
path: /opt/CAPEv2/storage/binaries/03db5c881378122fb2659be1836c3b6f521d1a0924af4c7db6367dc0ee207f86
crc32: 28E1708C
md5: a5fb49045c1360860536e136043f1c1e
sha1: 14900bd07a74e0bd069585b3c5aefbfb43655d43
sha256: 03db5c881378122fb2659be1836c3b6f521d1a0924af4c7db6367dc0ee207f86
sha512: ffd27c1f3497de596abc71800baa22a8bbba771b5199e69536c3636e95ce6adf61eac54de626ce22197f676917230591d1a641a7d4aa53817f15ee4f2b78e258
ssdeep: 24576:gyLd4B/Rzsvp2QVFoODubtpoqgETtuuHy/9//Zn:g5/JMnVFRSpoZE7EBh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138557E26F2E08C77D1F31A389D1BD2A85836BE002E39A5463BE53D0C6F397913566397
sha3_384: 4dd1cf2c8a6ac9b5b4d982097156b3f4dbbbbd6d5edfc494d247e4c7b260020ef8b66d3407f5dc39100bbd77103cda3d
ep_bytes: 558bec83c4f0b80cdc4700e8107ff8ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Delf.PLU also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.PWS.Gamania.38850
FireEyeGeneric.mg.a5fb49045c136086
CylanceUnsafe
Sangfor[ASPACK V2.12]
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.07a74e
BitDefenderThetaGen:NN.ZelphiF.34638.sTW@aubrvycc
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Delf.PLU
TrendMicro-HouseCallTROJ_GEN.R03BH0CE222
KasperskyTrojan.Win32.Agent.vccy
NANO-AntivirusTrojan.Win32.Gamania.brkamz
AvastWin32:Trojan-gen
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
IkarusTrojan-PWS.Win32.Gadu
AviraTR/Spy.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.Agent.GKSZFA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C5110005
Acronissuspicious
McAfeeArtemis!A5FB49045C13
VBA32Trojan.Agent
APEXMalicious
RisingTrojan.Generic@AI.88 (RDMK:cmRtazr+2D0nWv6uPnknLX5cHDYo)
YandexTrojan.GenAsa!2VqB8OHHNm4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.PLU!tr.spy
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Spy.Delf.PLU?

Win32/Spy.Delf.PLU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment