Backdoor

Should I remove “Backdoor:Win32/Mangit.A”?

Malware Removal

The Backdoor:Win32/Mangit.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Mangit.A virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

meuip.net.br
www.qualmeuip.com.br
www.ioam.org.cn

How to determine Backdoor:Win32/Mangit.A?


File Info:

crc32: 77827343
md5: 75dafbf000b1d561998ed25662bf568a
name: controler
sha1: d9aecea5197780c88c642f0b864391f5e5f3493a
sha256: 840ba5d779bb4ae19b951305fb2d7538dd3aad4d9cfdcb51cc5c8013e8ce14a8
sha512: d0cd36a252b027988b0b436d5c2217fefb02df9ff576a7e7cfcde35a3249337c64af3e560a4d8e9265d463ad5e759c6c4871ec4b6d3193e48f4f4680b3700f3f
ssdeep: 196608:eZnaPFIhT67Z+Q2+wHG0N8hcQ1MAQUkO4zYfDzv5lxDxhlcW81X2tsjrmiDV:eZnhlQ2TN8h1s4fvxbiBfjPDV
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: Window Manager
FileVersion: 3.0.0.0
CompanyName: Window Manager
ProductName: Window Manager
ProductVersion: 3.0.0.0
FileDescription: Gerenciador de Janelas do Windows
OriginalFilename: Gerenciador de Janelas do Windows
Translation: 0x0409 0x04e4

Backdoor:Win32/Mangit.A also known as:

MicroWorld-eScanTrojan.Generic.16443466
CAT-QuickHealBackdoor.Mangit
ALYacTrojan.Generic.16443466
CylanceUnsafe
ZillyaDropper.DapatoCRTD.Win32.29
BitDefenderTrojan.Generic.16443466
K7GWSpyware ( 004e23481 )
K7AntiVirusSpyware ( 004e23481 )
ArcabitTrojan.Generic.DFAE84A
TrendMicroTSPY_BANKER.YWNOQ
CyrenW32/Trojan.IYNK-1846
SymantecInfostealer.Bancos
TrendMicro-HouseCallTSPY_BANKER.YWNOQ
Paloaltogeneric.ml
GDataTrojan.Generic.16443466
KasperskyTrojan-Banker.Win32.Delf.gewe
NANO-AntivirusTrojan.Win32.Banker.edtole
RisingSpyware.Banker!8.8D (TFE:4:cBiESymsHDS)
Ad-AwareTrojan.Generic.16443466
EmsisoftTrojan.Generic.16443466 (B)
F-SecureTrojan.Generic.16443466
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Spy.Banker
JiangminTrojan.Banker.Delf.gw
AviraTR/Spy.Banker.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftBackdoor:Win32/Mangit.A
ZoneAlarmTrojan-Banker.Win32.Delf.gewe
AhnLab-V3Trojan/Win32.Banker.C1485342
McAfeeArtemis!75DAFBF000B1
AVwareTrojan.Win32.Generic!BT
VBA32TScope.Trojan.Delf
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Spy.Banker.ACYM
TencentWin32.Trojan.Falsesign.Ajly
YandexTrojanSpy.Banker!9Y4AyfCh+g4
AVGWin32:Trojan-gen
Cybereasonmalicious.000b1d
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.fb9

How to remove Backdoor:Win32/Mangit.A?

Backdoor:Win32/Mangit.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment