Backdoor

Should I remove “Backdoor:Win32/Talsab.C”?

Malware Removal

The Backdoor:Win32/Talsab.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Talsab.C virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

cust0.no-ip.org

How to determine Backdoor:Win32/Talsab.C?


File Info:

crc32: 48488ABC
md5: bc5d378a0d6e33ca3c4cc38b44c3277c
name: BC5D378A0D6E33CA3C4CC38B44C3277C.mlw
sha1: dde6d29f98f414127a6521c6f8bf81c6cd9bbe6f
sha256: 1e05606fe623230d4c599b41a33e0022318d76571ce714c02f475b75c75187a0
sha512: f9a2fd6c785b74b53f40142d5ce0e46334c133105880d2d1add1339885fa6a7adbbdff08f656587940c2a9d9ee5e8e934be7d7de51ae54a1041aadb3c1392d58
ssdeep: 24576:SEB67u0UiWJSPKltDV5EzXnhsakfgCMMOnL/fSjCgk0+0A:SEYSBPl1Vo7kfDMMOLqktv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Talsab.C also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.338102
FireEyeGeneric.mg.bc5d378a0d6e33ca
Qihoo-360Win32/TrojanSpy.Keylogger.HwUBOAUA
McAfeeArtemis!BC5D378A0D6E
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
BitDefenderGen:Variant.Zusy.338102
Cybereasonmalicious.a0d6e3
BitDefenderThetaGen:NN.ZelphiF.34590.lHW@aSNqa7aO
CyrenW32/Risk.EZOC-1810
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Swisyn.FF
APEXMalicious
AvastWin32:Talsab [Drp]
ClamAVWin.Trojan.Swisyn-1754
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/KeyLogger.c5758944
NANO-AntivirusTrojan.Win32.Yobdam.cdleg
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.Blocker!8.12A (TFE:4:G29ZdjksNnF)
Ad-AwareGen:Variant.Zusy.338102
SophosMal/Generic-S
ComodoMalware@#2qlrz88fmwbfw
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.MulDrop4.58214
ZillyaBackdoor.Yobdam.Win32.502
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
EmsisoftGen:Variant.Zusy.338102 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Swisyn.mwq
AviraDR/Delphi.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Backdoor]/Win32.Yobdam
MicrosoftBackdoor:Win32/Talsab.C
ArcabitTrojan.Zusy.D528B6
AhnLab-V3Trojan/Win32.Generic.C2102782
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.338102
CynetMalicious (score: 100)
VBA32TrojanDropper.Agent
ALYacGen:Variant.Zusy.338102
TACHYONBackdoor/W32.DP-Yobdam.1231360
MalwarebytesMalware.AI.4194432034
PandaGeneric Malware
TencentWin32.Trojan.Generic.Pgwr
YandexTrojan.GenAsa!aT84Ys+N30c
IkarusTrojan.Win32.Bredolab
eGambitUnsafe.AI_Score_99%
FortinetW32/Swisyn.NHT!tr
AVGWin32:Talsab [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.2008190.susgen

How to remove Backdoor:Win32/Talsab.C?

Backdoor:Win32/Talsab.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment