Trojan

Trojan.Win32.Mansabo.dsq malicious file

Malware Removal

The Trojan.Win32.Mansabo.dsq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Mansabo.dsq virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
ip.anysrc.net
181.86.68.138.zen.spamhaus.org
181.86.68.138.cbl.abuseat.org
181.86.68.138.b.barracudacentral.org
181.86.68.138.dnsbl-1.uceprotect.net
181.86.68.138.spam.dnsbl.sorbs.net

How to determine Trojan.Win32.Mansabo.dsq?


File Info:

crc32: 68BE1A81
md5: a2a51bc495aabbf1d466610164715c47
name: flygame.png
sha1: de1d0fc660ba865e84ce12f0265f83a2356b3371
sha256: 1f420c62c2492ba2182f684d8458fbdf36fd00420b16dde5ffea2011b8001b95
sha512: 46f78e8ba575565481182d528ea6d13e78d69e4f107e66ede67ac2474285b53aeaa9b0b65d9e7240a3de0f3438b264d5342a522b6f8b35e68ad9687ec4436520
ssdeep: 12288:r/Krvw0dDEW3Ngj3w+uCzd+e4SvNkrWoKzp/F1ey7CnN1:TKbDoj3w+uooqFFgy0b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: CalUser
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CalUser Application
ProductVersion: 1, 0, 0, 1
FileDescription: CalUser MFC Application
OriginalFilename: CalUser.EXE
Translation: 0x0409 0x04b0

Trojan.Win32.Mansabo.dsq also known as:

MicroWorld-eScanTrojan.Agent.EJCV
FireEyeTrojan.Agent.EJCV
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.Agent.EJCV
K7GWTrojan ( 0055d5e61 )
BitDefenderThetaGen:NN.ZexaE.33550.Uy1@aG5kQTai
AvastWin32:BankerX-gen [Trj]
GDataTrojan.Agent.EJCV
KasperskyTrojan.Win32.Mansabo.dsq
APEXMalicious
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.Agent.EJCV
F-SecureTrojan.TR/AD.TrickBot.monhx
EmsisoftTrojan.Agent.EJCV (B)
JiangminTrojan.Mansabo.ark
WebrootW32.Trojan.Emotet
AviraTR/AD.TrickBot.monhx
MAXmalware (ai score=83)
ArcabitTrojan.Agent.EJCV
ZoneAlarmTrojan.Win32.Mansabo.dsq
AhnLab-V3Trojan/Win32.Trickbot.C3641780
Acronissuspicious
ALYacTrojan.Agent.EJCV
TACHYONTrojan/W32.Mansabo.766133
ESET-NOD32a variant of Win32/Kryptik.GZLR
FortinetW32/Kryptik.GZLR!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM07.1.E5FD.Malware.Gen

How to remove Trojan.Win32.Mansabo.dsq?

Trojan.Win32.Mansabo.dsq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment