Spy Trojan

Trojan:Win32/CardSpy.DA!MTB removal tips

Malware Removal

The Trojan:Win32/CardSpy.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CardSpy.DA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/CardSpy.DA!MTB?


File Info:

name: BBA9BE5B5A5995625404.mlw
path: /opt/CAPEv2/storage/binaries/bdd400a51d57a672a4b17f42265c39c9272b6f36339acb678b9afc9c3fdd3497
crc32: 642CF94B
md5: bba9be5b5a5995625404d9192a439f5d
sha1: 82002e1e847e955d3c1da14e77030a8a987e4798
sha256: bdd400a51d57a672a4b17f42265c39c9272b6f36339acb678b9afc9c3fdd3497
sha512: aac78abb9145db5c90ef0110f1fb6cf983f447c7c7a6a718ff8458999e78238a199bbd5fd045746aa17ddc72689069420aa3d6d153db9e4fd463163ee3b8ddfa
ssdeep: 6144:KmwAB8xBKTDbuRO1/Y+LC4X33VVkbVMoSp0T5J5ZtmOyw:InKD6RO1/LX8MoSq/o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13AF49E11B6408034E3E6077689AAE5E51A796E381794E1CFF2A87D796B311D36B3330F
sha3_384: 065c03f531bc9d4f8ef017f7e872a7f50c17ca591e245aed6091da6957d90ebc5548edb7d53d5bac268dff5e19f776ac
ep_bytes: 897dd8750e8b45a88b3089459083c004
timestamp: 2013-09-23 08:21:17

Version Info:

0: [No Data]

Trojan:Win32/CardSpy.DA!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Fugrafa.280750
ClamAVWin.Malware.Urelas-9863836-0
FireEyeGeneric.mg.bba9be5b5a599562
ALYacGen:Variant.Fugrafa.280750
Cylanceunsafe
ZillyaTrojan.Wecod.Win32.15834
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.b5a599
BaiduWin32.Trojan.Urelas.d
VirITTrojan.Win32.Generic.CNSB
CyrenW32/Agent.GBY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Wecod.alk
BitDefenderGen:Variant.Fugrafa.280750
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.CardSpy.16000130
EmsisoftGen:Variant.Fugrafa.280750 (B)
F-SecureHeuristic.HEUR/AGEN.1300631
DrWebTrojan.Siggen5.60232
VIPREGen:Variant.Fugrafa.280750
TrendMicroTROJ_GEN.R03BC0DEM23
McAfee-GW-EditionBehavesLike.Win32.Generic.bz
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.MC64XC
JiangminTrojan.Wecod.axx
AviraHEUR/Patched.Ren
Antiy-AVLTrojan/Win32.Wecod
XcitiumTrojWare.Win32.Wecod.AL@55njeb
ArcabitTrojan.Fugrafa.D448AE
ZoneAlarmUDS:Trojan.Win32.Wecod.alk
MicrosoftTrojan:Win32/CardSpy.DA!MTB
GoogleDetected
McAfeeArtemis!BBA9BE5B5A59
MAXmalware (ai score=89)
MalwarebytesCardSpy.Spyware.Stealer.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DEM23
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
IkarusTrojan-PWS.Banker6
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Fugrafa.280750!tr
BitDefenderThetaGen:NN.ZexaF.36196.UmZ@aKwmMwj
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/CardSpy.DA!MTB?

Trojan:Win32/CardSpy.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment