Virus

Virus:Win32/Capsfin.A information

Malware Removal

The Virus:Win32/Capsfin.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Capsfin.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Operates on local firewall’s policies and settings
  • Attempts to disable Windows Auto Updates
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Virus:Win32/Capsfin.A?


File Info:

name: 8DAB96C018FACD3C896D.mlw
path: /opt/CAPEv2/storage/binaries/56954f4c17a462b4a43c3bdc4e70865cd50450884a7b666889368b9ed4baccd2
crc32: B07EE5A9
md5: 8dab96c018facd3c896d17c53d47cef2
sha1: ced35ceb4d436154d2caf0aac76f23f2f6a45b10
sha256: 56954f4c17a462b4a43c3bdc4e70865cd50450884a7b666889368b9ed4baccd2
sha512: ecac0a91ff8a597081345e6c9125b1981a6b361d4cfbd6ce17b4c7179e4ef71f48a4a47d1cfcadc8c7fa6cd6fa7b55cb50a41698d94bb6c3e560f86401d2a5db
ssdeep: 3072:gLv6wHJdkvY2+ydeYMvnWtmpzaVmS4Mo63HDU84gCevcaqtehpjZ4Sav5wz4uHD0:evTdkgM03utmQt4UXbuSsg94L6zw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153A41A2572D0F23AD021C6F43D2683A0977ABC3116E1A907F7C07F297AB1AA79634357
sha3_384: 4b17c8794356924905a0c9f9477ede7cf1ec7e7e5aa1750a09230ad0dde5ea6fa152cb1a8079ec369c41093c95a5d0aa
ep_bytes: e8062f0000e978feffff8bff566a0168
timestamp: 2012-09-07 06:30:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: Piperales
FileVersion: 9.41
ProductVersion: 9.41
InternalName: parcidentate
OriginalFilename: parcidentate.exe

Virus:Win32/Capsfin.A also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Dzan.C
CAT-QuickHealW32.Swisyn.A
ALYacWin32.Dzan.C
MalwarebytesPronny.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0040f2f81 )
K7GWEmailWorm ( 0040f2f81 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.VBObfus.f
VirITWin32.Capsfin.A
CyrenW32/Dzan.B
SymantecW32.Mibling
Elasticmalicious (high confidence)
ESET-NOD32Win32/Comrerop.C
APEXMalicious
ClamAVWin.Packer.VBCrypt-5731517-0
KasperskyTrojan-Dropper.Win32.Dycler.pka
BitDefenderWin32.Dzan.C
NANO-AntivirusTrojan.Win32.Autorun.bemdrp
AvastWin32:Downloader-EMH [Trj]
TencentMalware.Win32.Gencirc.10b8f0b2
EmsisoftWin32.Dzan.C (B)
F-SecureTrojan.TR/VB.Symmi.1355987
DrWebTrojan.VbCrypt.60
VIPREWin32.Dzan.C
McAfee-GW-EditionBehavesLike.Win32.Virut.gz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8dab96c018facd3c
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Capsfin.A
JiangminTrojan.Generic.ayhlk
GoogleDetected
AviraTR/VB.Symmi.1355987
MAXmalware (ai score=87)
Antiy-AVLTrojan[Dropper]/Win32.Dycler
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitWin32.Dzan.C
ViRobotWin32.Capsfin.A
ZoneAlarmTrojan-Dropper.Win32.Dycler.pka
MicrosoftVirus:Win32/Capsfin.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Tinfo
McAfeeTrojan-FACE!8DAB96C018FA
TACHYONTrojan/W32.FirewallBypass.479232
VBA32Worm.AutoRun
Cylanceunsafe
ZonerProbably Heur.ExeHeaderL
RisingVirus.Comrerop!1.6748 (CLASSIC)
YandexTrojan.GenAsa!Oc4u/NQI+nc
IkarusTrojan-Downloader.Win32.Beebone
MaxSecureVirus.Win32.Agent.CNFX
FortinetW32/Comrerop.AX!tr
BitDefenderThetaAI:FileInfector.650223E50C
AVGWin32:Downloader-EMH [Trj]
Cybereasonmalicious.018fac
DeepInstinctMALICIOUS

How to remove Virus:Win32/Capsfin.A?

Virus:Win32/Capsfin.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment