Spy

Win32/Spy.Delf.QWP removal tips

Malware Removal

The Win32/Spy.Delf.QWP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.QWP virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Harvests cookies for information gathering

How to determine Win32/Spy.Delf.QWP?


File Info:

name: 7A1A5F63A716CE060892.mlw
path: /opt/CAPEv2/storage/binaries/e4d34972b9db69f661425d869590775cddb09cd61e45bb168c8cfb17d13a086d
crc32: 27269D41
md5: 7a1a5f63a716ce0608926ef51c9ebc0c
sha1: f9acc2412b8d949fc139ffb182c2aca417a9574a
sha256: e4d34972b9db69f661425d869590775cddb09cd61e45bb168c8cfb17d13a086d
sha512: 940dd7fed916752667817a4ad54d52fa5a133b68abbb62edf70279243f81b636cc4cecd2c741380a93b9a8a80fc0e32703cb239e0bfddb1763cb738169ff0806
ssdeep: 1536:X0j+84T8bivhkKCoVRpfujc/YwmXKeXWhAaG8xDMmWoQUnUo2b:X0v4Yb2eruGgAaeXWhTj+f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E83028DE24A4C45D879C7F11322A73B2CE57C822A79C70F1C1225F62AF6BB64C5B719
sha3_384: b1873f560c946e932fe24ff0de35ffa2d6124c281a48966cc54a91f881ac6c8496f29f6e9396c8c335ef975db3b988be
ep_bytes: 60be00a042008dbe0070fdffc78708d7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Delf.QWP also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen3.61405
MicroWorld-eScanTrojan.Agent.CGVL
FireEyeGeneric.mg.7a1a5f63a716ce06
CAT-QuickHealTrojan.GenericIH.S24070444
McAfeeArtemis!7A1A5F63A716
CylanceUnsafe
VIPRETrojan.Agent.CGVL
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWTrojan ( 0059716d1 )
ArcabitTrojan.Agent.CGVL
BitDefenderThetaAI:Packer.645D753C23
CyrenW32/Legendmir.JCFQ-5826
SymantecW32.HLLP.Philis
ESET-NOD32a variant of Win32/Spy.Delf.QWP
APEXMalicious
ClamAVWin.Trojan.Lmir-24
KasperskyTrojan-GameThief.Win32.Lmir.oa
BitDefenderTrojan.Agent.CGVL
NANO-AntivirusTrojan.Win32.Lmir.dxaowj
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.Syphilis.a
Ad-AwareTrojan.Agent.CGVL
SophosW32/LegMir-BM
ComodoTrojWare.Win32.PSW.Legendmir.OA@3b0u
BaiduWin32.Trojan-PSW.OLGames.be
ZillyaTrojan.Lmir.Win32.762
TrendMicroPE_LEGMIR.B
McAfee-GW-EditionPWS-CangKu
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Agent.CGVL (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.LMir.ec
WebrootW32.Malware.Gen
GoogleDetected
AviraW32/PSW.Lmir.oa
Antiy-AVLTrojan/Generic.ASMalwS.206
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.A.PSW-Lmir.212992[UPX]
GDataWin32.Trojan.PSE1.BP07YY
CynetMalicious (score: 100)
AhnLab-V3Win32/Lemir.212992
VBA32Trojan.Sabsik.FL
ALYacTrojan.Agent.CGVL
MAXmalware (ai score=82)
MalwarebytesMalware.AI.2382208213
TrendMicro-HouseCallPE_LEGMIR.B
RisingTrojan.PSW.Qiji.s (TFE:5:etY0vUvUINB)
YandexTrojan.GenAsa!l4kdDOnxqiQ
TACHYONVirus/W32.Philis
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3a716c

How to remove Win32/Spy.Delf.QWP?

Win32/Spy.Delf.QWP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment