Spy Trojan

Trojan:Win32/CardSpy!pz removal instruction

Malware Removal

The Trojan:Win32/CardSpy!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CardSpy!pz virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid

How to determine Trojan:Win32/CardSpy!pz?


File Info:

name: CCF95254AED24CB9F3F4.mlw
path: /opt/CAPEv2/storage/binaries/64b636e24442b7ad57c1f37e7c64e30ff425b77d98ea2c868c7e2c9894b5bce2
crc32: F41CEFA2
md5: ccf95254aed24cb9f3f406271bdbd355
sha1: 807cfa8d24469265c35fad39f80758d23d23d089
sha256: 64b636e24442b7ad57c1f37e7c64e30ff425b77d98ea2c868c7e2c9894b5bce2
sha512: 676700bb1fa8e3aa3ea442fa924d94a1658d16096f9b48c9827c0060a2469c91b304dd6be63fb842c73b01c19cd960c82cd5c7520899f16211fce9ebd6d1df3c
ssdeep: 6144:1GBZ7s0bRIqFjjBmNFXRMBYee+FHfKHLtV7FRfVA8llc8dO3dsmtLjUFLKp0X:IcsfBYee+F/KHxV7FRmYh83dsm5jUFzX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109E47C1176908031E7A617724A5AE6F01A7DBD381BA5D6CFF6A43A395E301D38A3730F
sha3_384: 8af1a89ee5225db4ca11bba4cc790d828f5963c3757087612ab78309a6ff9b1c74a10e84c7f672f7b22d9a72c1f9cfec
ep_bytes: e8f3800000e979feffff8bff558bec51
timestamp: 2013-10-30 08:31:44

Version Info:

0: [No Data]

Trojan:Win32/CardSpy!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.ccf95254aed24cb9
CAT-QuickHealTrojan.Bulta.B3
SkyhighBehavesLike.Win32.Generic.jt
McAfeeGenericATG-FVK!CCF95254AED2
MalwarebytesCardSpy.Spyware.Stealer.DDS
VIPREGen:Heur.Mint.SP.Urelas.1
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0048c72d1 )
K7GWSpyware ( 0048c72d1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Urelas.d
VirITTrojan.Win32.Generic.HQH
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Spy.CardSpy.NAF
APEXMalicious
ClamAVWin.Malware.Urelas-9863836-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.CardSpy.cqwefm
AvastWin32:Malware-gen
TencentTrojan.Win32.CardSpy.16000130
SophosTroj/Cardspy-C
F-SecureTrojan.TR/AD.CardSpy.gixta
DrWebTrojan.AVKill.33739
ZillyaTrojan.CardSpy.Win32.9
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
IkarusTrojan-PWS.Banker6
GDataWin32.Trojan.PSE.102K66A
JiangminTrojan/Generic.bfnrg
GoogleDetected
AviraTR/AD.CardSpy.gixta
VaristW32/Injector.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Wecod
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Small.NAF@531prv
ArcabitTrojan.Mint.SP.Urelas.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/CardSpy!pz
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R305285
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.QmX@aG2Z4tlO
MAXmalware (ai score=82)
VBA32Trojan.AVKill
Cylanceunsafe
PandaTrj/Genetic.gen
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/CardSpy.NAF!tr
AVGWin32:Malware-gen
Cybereasonmalicious.d24469
DeepInstinctMALICIOUS

How to remove Trojan:Win32/CardSpy!pz?

Trojan:Win32/CardSpy!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment