Spy

Win32/Spy.Donot.C removal

Malware Removal

The Win32/Spy.Donot.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Donot.C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Manipulates data from or to the Recycle Bin
  • Creates an autorun.inf file
  • Authenticode signature is invalid

How to determine Win32/Spy.Donot.C?


File Info:

name: 8CB489B36754821DD9EE.mlw
path: /opt/CAPEv2/storage/binaries/64c0c93e37da410a2f8da416046e5d3d5f17fe0ee4e73c01c9d9fc570a647f19
crc32: CCB8119B
md5: 8cb489b36754821dd9eea881508e4eb5
sha1: 39f92cbec05785bf9ff28b7f33906c702f142b90
sha256: 64c0c93e37da410a2f8da416046e5d3d5f17fe0ee4e73c01c9d9fc570a647f19
sha512: be1c0ac00010c67481c37591a1c20e67c8d3d46ecb35fc96414e03f8a5c988b91abdfc57d66e7f660eea192b955a58f98fd01c2fd37c5ccf79ee3b8c34bd937b
ssdeep: 12288:vmxMRSB8jiY6qTdhzzmYDtUcZ6n0kMT1/ghEpNbniJ7u3IT:vk8OqTdhzzmYFZ6n0kbEHbWnT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BA44C01B6E1C034F4F716F95DBEA1A8983DBDA0172490DB63C42AED5A35EE0AD31727
sha3_384: 97b500c764ca7ff816a872d04babb3b069de0b4af558fdc220895a2a8fc458a39518ccb8ebd60a4817dcc0b2e7c5f12a
ep_bytes: 558bece838fdffff5dc3cccccccccccc
timestamp: 2021-09-27 09:12:34

Version Info:

0: [No Data]

Win32/Spy.Donot.C also known as:

BkavW32.AIDetect.malware2
CylanceUnsafe
BitDefenderThetaGen:NN.ZexaF.34062.DqX@aajsm2h
ESET-NOD32Win32/Spy.Donot.C
KasperskyTrojan.Win32.Udochka.ajv
AvastWin32:Trojan-gen
F-SecureTrojan.TR/Spy.Agent.xxljz
McAfee-GW-EditionArtemis
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
GDataWin32.Trojan.Agent.2VUAKR
AviraTR/Spy.Agent.xxljz
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!8CB489B36754
YandexTrojan.Udochka!j6gXlpb4krg
AVGWin32:Trojan-gen

How to remove Win32/Spy.Donot.C?

Win32/Spy.Donot.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment