Spy

Should I remove “Win32/Spy.Delf.RAQ”?

Malware Removal

The Win32/Spy.Delf.RAQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Delf.RAQ virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Spy.Delf.RAQ?


File Info:

name: EBA2C8358D62C3D63BC1.mlw
path: /opt/CAPEv2/storage/binaries/23a4440bd30f5d8bb25ac01f5cff1f18c03867cf466f1832bb0b466a9db6d625
crc32: 3A244D39
md5: eba2c8358d62c3d63bc1e47e09faa2b5
sha1: 9fae1b3e354f5b251d017184bd5da4a35c1c0f01
sha256: 23a4440bd30f5d8bb25ac01f5cff1f18c03867cf466f1832bb0b466a9db6d625
sha512: 2fd59240f3812a824105b604b39c930dea80609c9678997d256f8aea61f1c6ec3ea251057a3102704f5e5ae16ee2f0d2e4d3e6e8f942c8f9d49ea2d1486cefd2
ssdeep: 3072:lzRMrBItGE4K5rEcRZzFPk2I111KYTI1Uk1I:lzRsBXE4K5hHMzTy1I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D048B49B3FDED4DC83A1C30B88088D2C7D9E4E1DEC22C45A6D4661EAEEA147F51265F
sha3_384: 403924b7aea0970c5ee5c23156b7cced93b9aa65216bf7c522f9b7293bd99b54963548c9626eb5070ce63702f89b9e73
ep_bytes: 8bec609ce99a380000006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: MSbuild Inc
FileDescription: MSbuild Component Registrant
FileVersion: 2.1.4.0
LegalCopyright: Copyright © 2004 MSbuild Inc. All Rights Reserved
ProductName: MSbuild
ProductVersion: 2.1.4.0
Translation: 0x0409 0x04e4

Win32/Spy.Delf.RAQ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.63810156
McAfeeGenericRXUR-MM!EBA2C8358D62
CylanceUnsafe
VIPRETrojan.GenericKD.63810156
SangforTrojan.Win32.Agent.Vjfs
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanSpy:Win32/Basine.65befb52
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e354f5
CyrenW32/LdPinch.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Delf.RAQ
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.63810156
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:BackdoorX-gen [Trj]
Ad-AwareTrojan.GenericKD.63810156
TACHYONTrojan/W32.Agent.174592.TB
EmsisoftTrojan.GenericKD.63810156 (B)
ComodoTrojWare.Win32.PkdMorphine.~AN@1l4q0o
DrWebTrojan.PWS.Webmonier.924
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.eba2c8358d62c3d6
SophosMal/Basine-C
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1HFWLIB
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Generic.D3CDAA6C
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R535751
ALYacTrojan.GenericKD.63810156
MAXmalware (ai score=81)
VBA32Heur.Trojan.Hlux
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_GEN.R002H0CKP22
RisingBackdoor.Hupigon!8.B57 (TFE:3:9ZR3ES2hAvB)
IkarusTrojan-GameThief.Win32.Magania
MaxSecureTrojan.Malware.193645978.susgen
FortinetW32/PossibleThreat
AVGWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/Spy.Delf.RAQ?

Win32/Spy.Delf.RAQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment