Spy

About “Win32/Spy.Grandoreiro.CB” infection

Malware Removal

The Win32/Spy.Grandoreiro.CB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Grandoreiro.CB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Spy.Grandoreiro.CB?


File Info:

name: 136E03F55F291335CDD5.mlw
path: /opt/CAPEv2/storage/binaries/f8bbc11ab50e59dc92c73f5ceb7355ef9bfea64f1c80c5a58ec90833f7b2c26c
crc32: 441DF3A7
md5: 136e03f55f291335cdd581f11b13e467
sha1: bdbed005084bf746e16df1b6bd3b2db374ab3c4b
sha256: f8bbc11ab50e59dc92c73f5ceb7355ef9bfea64f1c80c5a58ec90833f7b2c26c
sha512: a26d6729571336e89be3d3144bed4d538ddd04a3cb558e135b7e2f980203027cb397e0f81bd86dc0c77e1232a8e3f21dfcb69ce0acead453e8b21e8924a38212
ssdeep: 49152:8pO6RHlCdrndI4jJip/nSks/W4S6spjVKzM2dVc2Ln2t:wO6RHlGr4DIspVKzTet
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1E4F57D23B344653EC05B1A3A5967D328993BF77126268C5B67F40CCC8F399823E3A657
sha3_384: a6781ecbe6886a3c244e1785c79f381dc51dbaa7b2e501e436bffa070be97e9286a1785a484fd372bca35ad05061321f
ep_bytes: 558bec83c4c0b8fc236900e8b825d7ff
timestamp: 2023-12-20 14:39:57

Version Info:

0: [No Data]

Win32/Spy.Grandoreiro.CB also known as:

BkavW32.Common.4A6FA775
LionicTrojan.Win32.Grandoreiro.7!c
AVGWin32:SpywareX-gen [Trj]
MicroWorld-eScanGen:Variant.Barys.412050
FireEyeGen:Variant.Barys.412050
SkyhighBehavesLike.Win32.BadFile.wh
McAfeeGenericRXAA-AA!136E03F55F29
ZillyaTrojan.Grandoreiro.Win32.2764
SangforSpyware.Win32.Grandoreiro.Vzfv
K7AntiVirusSpyware ( 005a3d9b1 )
AlibabaTrojanBanker:Win32/Grandoreiro.feaecb18
K7GWSpyware ( 005a3d9b1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Grandoreiro.CB
CynetMalicious (score: 100)
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Grandoreiro.gen
BitDefenderGen:Variant.Barys.412050
AvastWin32:SpywareX-gen [Trj]
TencentMalware.Win32.Gencirc.13faa278
EmsisoftGen:Variant.Barys.412050 (B)
F-SecureHeuristic.HEUR/AGEN.1364204
VIPREGen:Variant.Barys.412050
TrendMicroTROJ_GEN.R002C0XLM23
SophosMal/Generic-S
WebrootW32.Infostealer.Gen
VaristW32/ABSpyware.BRSS-8077
AviraHEUR/AGEN.1364204
MAXmalware (ai score=81)
Antiy-AVLTrojan[Spy]/Win32.Grandoreiro
KingsoftWin32.Trojan-Banker.Grandoreiro.gen
MicrosoftTrojan:Win32/Malgent!MSR
XcitiumMalware@#2ueanrof4l7sl
ArcabitTrojan.Barys.D64992
ViRobotTrojan.Win.Z.Grandoreiro.3425280
ZoneAlarmUDS:Trojan-Banker.Win32.Grandoreiro.gen
GDataGen:Variant.Barys.412050
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5464208
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Barys.412050
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0XLM23
RisingSpyware.Grandoreiro!8.F2CC (TFE:6:tzrc7MyXliU)
IkarusTrojan-Spy.Win32.Grandoreiro
MaxSecureTrojan.Malware.102062852.susgen
FortinetW32/Grandoreiro.CB!tr.spy
DeepInstinctMALICIOUS
alibabacloudTrojan[stealer]:Win/Grandoreiro.CB

How to remove Win32/Spy.Grandoreiro.CB?

Win32/Spy.Grandoreiro.CB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment