What is CasPol.exe?
Originally developed by Microsoft Corporation, CasPol.exe is a legitimate file process and also called as Microsoft.NET Framework CAS Policy Manager that is associated with Microsoft.NET Framework software. It is located in C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ Files by default.
CasPol.exe virus is created when malware authors write virus files and name them after CasPol.exe with an aim to spread virus on the internet.
Affected Platform: Windows OS
How to check if your computer is infected with CasPol.exe malware?
If your system is affected by CasPol.exe malware, you will notice one or the several below symptoms:
- CasPol.exe occupies an unusually large CPU memory
- Erratic internet connection
- Your browser is bombarded with annoying popup ads
- Computer screen freezes
- PC's processing speed suffers
- You are redirected to unknown websites
To pinpoint the virus file location, take the following steps:
Step 1: Press CTRL+ALT+DEL keys at once to open Task Manager.
Step 2: If you notice the file located outside C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ Files you should run an antivirus scan to get rid of the malware.
How to remove CasPol.exe malware from system using Comodo Cleaning Essentials?
You can either choose to remove CasPol.exe and other malwares using Comodo Antivirus, or Comodo Cleaning Essentials (CCE) – both of which are absolutely free to download! CCE is a set of computer security tools designed to help you identify and remove malwares and unsafe processes from an infected computer.
To remove malwares using CCE, take the following steps:
1. Check the system requirements and download the feature-rich CCE suite for free.
2. After installation, choose the type of scan you want to perform. CCE offers 3 scan options to get rid of malwares from a PC:
- Smart Scan: Does a scan on critical areas of your system.
- Full Scan: Does a complete scan of your system.
- Custom Scan: Does a scan only on selected items.
The process to initiate the above mentioned scans are self-explanatory and thus, easy-to-use.
Additionally, it's recommended that you approve of any updates that the CCE will prompt you about to ensure it does a better job of identifying all the latest threats.
3. Click 'Next' to view the results.
Regardless of the type of scan you choose, the results will sometimes show false positive (flagging files that are actually safe), which has to be ignored. Only select the files you want to get rid of.
4. Click 'Apply' to apply the selected operations to the threats. The selected operations will be applied.
No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
---|---|---|---|---|---|---|---|---|---|---|
1 | Microsoft Corporation | Executable | 9810d49e30c40791 eceec50702e9e19d e46e4ccb |
34b4c0996a7fee59 bbc91b1b6ad1d6da |
Virus.Win32. Sality.K |
No | 2.0.50727. 42 (RTM.05072 7-4200) |
2.0.50727. 42 |
Brazil | N/A |
2 | N/A | Executable | f2cc1545a7ef36b4 a9f35521c091b0f7 24b5df99 |
b35ba109173e0a21 dfaad5d813795214 |
Win32.Neshta .A |
No | N/A | N/A | 181.66.169.99/32 | N/A |
3 | Microsoft Corporation | Executable | eb3879d6e9a23143 5b7d656b4764db9c 9d7903a5 |
19fc6facc454fd59 4872107c3a9978e2 |
P2PWorm.Win3 2.Bacteraloh .h |
No | 1.1.4322.5 73 |
1.1.4322.5 73 |
Russian Federation | N/A |
4 | N/A | Executable | a0d36ea8564765ba 438f5106ca5eb39c e4f7af65 |
eccbe35724c28923 1caeb966d02cc335 |
Win32.Neshta .A |
No | N/A | N/A | 181.66.169.99/32 | N/A |
No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
---|---|---|---|---|---|---|---|---|
1 | Microsoft Corporation | Executable | a5f2d722963bcd5b 781d6cf19d26c929 b9157f82 |
a40f519343854c3c 75aff6a5c44b21e6 |
Yes | 4.6.1081.0 built by: NETFXREL3S TAGE |
4.6.1081.0 | United States |
2 | Microsoft Corporation | Executable | 5ee37caaa0acbe0b 0d34c7a30aa68645 2e318d1c |
c90aac6bdf0f0c5b dc2728a79c18e131 |
Yes | 4.0.30319. 1 (RTMRel.03 0319-0100) |
4.0.30319. 1 |
10.224.1.61/32 |
3 | Microsoft Corporation | Executable | 4534f039a96d3da3 61a7bc6b1269dbb6 d20e2527 |
33733706c7a3590b 4ae76c6130c5ac75 |
No | 2.0.50727. 3053 (netfxsp.0 50727-3000 ) |
2.0.50727. 3053 |
10.224.1.55/32 |
4 | Microsoft Corporation | Executable | 4b545dfc3aa51879 da860aeba883d7d2 751c512c |
d0257b797499b17f c735772b02d7ed88 |
Yes | 4.7.2558.0 built by: NET471REL1 |
4.7.2558.0 | United States |