Spy

How to remove “Win32/Spy.Casbaneiro.DK”?

Malware Removal

The Win32/Spy.Casbaneiro.DK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Casbaneiro.DK virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Spy.Casbaneiro.DK?


File Info:

name: 171BFE5B262DDAC34C33.mlw
path: /opt/CAPEv2/storage/binaries/2287543de088a911db7debe3901f7f15bf03df0310de7d6a9a7b2385d3e6ce2a
crc32: 49BE015A
md5: 171bfe5b262ddac34c330e7f6f04c94b
sha1: ab70d80245422f468b92ea5f7c40cb0bbb993c2d
sha256: 2287543de088a911db7debe3901f7f15bf03df0310de7d6a9a7b2385d3e6ce2a
sha512: 0cf9f75d2b22150db2203086dd47293306177047f62324a0a04626832b9096bde7b4af0b2089d5cb3e60395d25e6807671a10df3d6358d92c652638ff5b80a90
ssdeep: 49152:T2Yfto9a4NfG9KEXBRwSBNjFkHtMUt3wJ//MVUvEgTpTjIJ97qyOOCyOOmb:T2faV9K4yt32/MVUvE4OGyOOCyOOmb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106F53A327240383AC16A0E3658737654583E7BA165CA8D1B7EB39B5C8F35181F92AF4F
sha3_384: 475094d181fd5a51d08e2e5c1dee1c98ff2d17ac24939cdb6e4efcf359e246dd95cd6cabff36328e27567e7c12223960
ep_bytes: 558bec83c4f0b8182c6600e8fc04daff
timestamp: 2022-01-23 19:23:29

Version Info:

CompanyName: ywxjbeuia
FileDescription: keeg yih
FileVersion: 2.3.7.6
InternalName: f kxamq
ProductName: zezsqbyi cpjbalb
ProductVersion: 2.3.7.6
Comments: b mrhtb kgsvryhxczwxtmrgkq
Translation: 0x0409 0x04e4

Win32/Spy.Casbaneiro.DK also known as:

BkavW32.Common.6702CFC2
LionicTrojan.Win32.Casbaneiro.b!c
MicroWorld-eScanTrojan.GenericKD.71666529
FireEyeTrojan.GenericKD.71666529
SkyhighBehavesLike.Win32.Dropper.wh
McAfeeArtemis!171BFE5B262D
Cylanceunsafe
ZillyaTrojan.Casbaneiro.Win32.742
SangforSpyware.Win32.Casbaneiro.V5zr
CrowdStrikewin/malicious_confidence_60% (W)
K7GWSpyware ( 0058de7f1 )
K7AntiVirusSpyware ( 0058de7f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Casbaneiro.DK
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Dropper.Win32.Delf
BitDefenderTrojan.GenericKD.71666529
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.13fffda7
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Casbaneiro.ejnsc
VIPRETrojan.GenericKD.71666529
TrendMicroTROJ_GEN.R002C0WB524
EmsisoftTrojan.GenericKD.71666529 (B)
IkarusTrojan-Spy.Win32.Casbaneiro
GDataTrojan.GenericKD.71666529
VaristW32/ABSpyware.TDHX-8534
AviraTR/Spy.Casbaneiro.ejnsc
Antiy-AVLTrojan[Spy]/Win32.Casbaneiro
KingsoftWin32.Troj.Undef.a
ArcabitTrojan.Generic.D4458B61
ZoneAlarmUDS:Trojan-Dropper.Win32.Delf
MicrosoftTrojan:Win32/Mamson.A!ac
GoogleDetected
ALYacTrojan.GenericKD.71666529
MAXmalware (ai score=87)
MalwarebytesNeshta.Virus.FileInfector.DDS
PandaTrj/Agent.ALS
TrendMicro-HouseCallTROJ_GEN.R002C0WB524
RisingTrojan.Generic@AI.100 (RDML:bCunKTW8j/KhBtpV9gmnaQ)
MaxSecureTrojan.Malware.184561318.susgen
FortinetW32/Casbaneiro.DK!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Win32/Spy.Casbaneiro.DK?

Win32/Spy.Casbaneiro.DK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment