Spy

About “Win32/Spy.Ousaban.B” infection

Malware Removal

The Win32/Spy.Ousaban.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Ousaban.B virus can do?

  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Spy.Ousaban.B?


File Info:

name: ED630A560DEEF0C84303.mlw
path: /opt/CAPEv2/storage/binaries/b760ee0e5283c9226a26dc747bc3e7445154f42c536d256ef6bb1fe4d692b3a5
crc32: 970C7F23
md5: ed630a560deef0c84303dac067936328
sha1: 658ae465f9ca6c0ca723f08b9d095c9ef7dcf226
sha256: b760ee0e5283c9226a26dc747bc3e7445154f42c536d256ef6bb1fe4d692b3a5
sha512: 7e2c9ca6b01064fe1bc0bf3c6de76e2cf38d891080e089c17bb7528917e5eb500fd052d459e12c1367d7648cff83a6aa530f24d339e89b8748c0893edb3a9fc2
ssdeep: 196608:AmQhb5sXfboYcag2YDVekUamtH72emtsnH8u7eVrYY8GDjVH:Ab5yfcagrgkUZ2TtsD7aV/VH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0961236A751BBB6CDA5133000F31B153E7398B157F222567F209A2E3C6B7807AA5BC5
sha3_384: 0f300cdc27be6657bf164790a890f1e705ac02f704571e2f605452908ddcc889274ba1fce267d3cc6e98b61cabe262e4
ep_bytes: e800070000e9000000006a5868687240
timestamp: 2000-11-24 11:50:57

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Autoextrator de arquivo de gabinete Win32
FileVersion: 11.00.19041.3324 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Todos os direitos reservados.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.19041.3324
Translation: 0x0416 0x04b0

Win32/Spy.Ousaban.B also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
K7AntiVirusSpyware ( 005785951 )
K7GWSpyware ( 005785951 )
ESET-NOD32a variant of Win32/Spy.Ousaban.B
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.Javali.gen
AvastWin32:Agent-BCYT [Drp]
RisingMalware.SwollenFile!1.E38A (CLASSIC)
F-SecureTrojan.TR/Spy.Banker.Gen
Trapminemalicious.high.ml.score
IkarusTrojan-Downloader.JS.Banload
GoogleDetected
AviraTR/Spy.Banker.Gen
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmHEUR:Trojan-Banker.Win32.Javali.gen
AVGWin32:Agent-BCYT [Drp]

How to remove Win32/Spy.Ousaban.B?

Win32/Spy.Ousaban.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment