Trojan

Trojan.Win32.Mansabo.edn removal instruction

Malware Removal

The Trojan.Win32.Mansabo.edn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Mansabo.edn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

ident.me
apps.identrust.com

How to determine Trojan.Win32.Mansabo.edn?


File Info:

crc32: A811C766
md5: f012be6bc189fc9070ff4047c29b83bd
name: flygame.png
sha1: 2f9557f58a3e04f05ff487031099dd483a28f93b
sha256: c6f2c82c7be28226c9121e4b72f98928e2c756708fec69e9b5098000f901b440
sha512: da461d1ee622daad21a6a9d1b2c8848acd48e5ed197455c42f6d8ac5dbe1cde3f3c61b22dca1cbf8ff52a5190bb0c3b51f61c50a37732f3a7217f11d4687d0ca
ssdeep: 12288:ZAH7FWwJuaw7uc+sSGBZAbRC3t+EMZnWrXxC6Wy8H:36c+sSGBZAbRYvMixMH
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: CMap
FileVersion: 1.0.0.0
CompanyName: Ricky Bull
Comments: clsASMpic is a simple class that makes possible
ProductName: Character Map
ProductVersion: 1.0.0.0
OriginalFilename: CMap.exe

Trojan.Win32.Mansabo.edn also known as:

MicroWorld-eScanTrojan.Agent.EKSK
McAfeeGenericRXAA-AA!F012BE6BC189
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.Agent.EKSK
Cybereasonmalicious.58a3e0
Invinceaheuristic
APEXMalicious
GDataTrojan.Agent.EKSK
KasperskyTrojan.Win32.Mansabo.edn
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.EKSK (B)
F-SecureTrojan.TR/AD.TrickBot.byib
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.f012be6bc189fc90
WebrootW32.Trojan.Trickbot
AviraTR/AD.TrickBot.byib
ArcabitTrojan.Agent.EKSK
ZoneAlarmTrojan.Win32.Mansabo.edn
AhnLab-V3Trojan/Win32.Agent.C3974862
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34084.Cm1@aKtvLsgm
MAXmalware (ai score=88)
ESET-NOD32a variant of Win32/Injector.EKFY
RisingTrojan.Trickbot!8.E313 (C64:YzY0OmI0hATdhqtF)
SentinelOneDFI – Malicious PE
Ad-AwareTrojan.Agent.EKSK
PandaTrj/TrickBot.A
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.E31F.Malware.Gen

How to remove Trojan.Win32.Mansabo.edn?

Trojan.Win32.Mansabo.edn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment