Trojan

Trojan-PSW.Win32.Disbuk.abq (file analysis)

Malware Removal

The Trojan-PSW.Win32.Disbuk.abq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Disbuk.abq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs

How to determine Trojan-PSW.Win32.Disbuk.abq?


File Info:

crc32: AE69A8F5
md5: 9193f99d1c6934fe47a436735f879931
name: 3.exe_
sha1: caee08134f0925286048afaee7eeaa2d46fd667a
sha256: 7c9eeac634ce6e1fb9079de077d07df63062a38626c59243f5b24f1d8924d60a
sha512: b332e2051f0bf27db5a75d99e9bd4aaa3d0486e2c77f791e87a63f23bc5120377ea60974747402baa31e0ce401d85b0048e9ee3f33e4042710edfd3ceb475d4d
ssdeep: 24576:BTfEsP85DgJrivY05+QazQnxxkAVEhS9pwbRmvez1nwiyPKNjrth2Z5pHSAMSYEQ:FcsQ6QNnxEgp+kEt/yiJpSbSAMN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: ybtickets
Comments: This installation was built with Inno Setup.
ProductName: ybtickets
ProductVersion: 1.56
FileDescription: ybtickets Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Trojan-PSW.Win32.Disbuk.abq also known as:

DrWebTrojan.PWS.Stealer.28423
MicroWorld-eScanTrojan.GenericKD.33812587
McAfeeArtemis!9193F99D1C69
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Disbuk.i!c
SangforMalware
K7AntiVirusSpyware ( 005484541 )
BitDefenderTrojan.GenericKD.33812587
K7GWSpyware ( 005484541 )
BitDefenderThetaGen:NN.ZexaF.34110.DmW@aqQ6iwjj
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R01FC0WEB20
GDataTrojan.GenericKD.33812587
KasperskyTrojan-PSW.Win32.Disbuk.abq
AlibabaTrojanPSW:Win32/Disbuk.2cfd8bd9
NANO-AntivirusTrojan.Win32.Stealer.hjkuwj
ViRobotTrojan.Win32.Z.Socelars.1934985
TencentWin32.Trojan-qqpass.Qqrob.Hsid
Ad-AwareTrojan.GenericKD.33812587
SophosMal/Generic-S
ComodoMalware@#2bu9tztgql2ll
F-SecureHeuristic.HEUR/AGEN.1122966
TrendMicroTROJ_GEN.R01FC0WEB20
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.33812587 (B)
IkarusTrojan-Spy.Agent
CyrenW32/Trojan.PCVP-2833
MaxSecureTrojan.Malware.101084981.susgen
Aviraappdiskscan.exe
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D203F06B
ZoneAlarmTrojan-PSW.Win32.Disbuk.abq
MicrosoftTrojan:Win32/Occamy.AA
VBA32TrojanPSW.Disbuk
MAXmalware (ai score=85)
MalwarebytesSpyware.Socelars
APEXMalicious
ESET-NOD32a variant of Win32/Spy.Socelars.S
RisingSpyware.Agent!1.B4DA (CLOUD)
FortinetW32/Socelars.S!tr.spy
WebrootW32.Adware.Gen
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
Qihoo-360Win32/Trojan.PWS.d75

How to remove Trojan-PSW.Win32.Disbuk.abq?

Trojan-PSW.Win32.Disbuk.abq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment