Trojan

About “Trojanpws.Disbuk” infection

Malware Removal

The Trojanpws.Disbuk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojanpws.Disbuk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

www.ipcode.pw

How to determine Trojanpws.Disbuk?


File Info:

crc32: C4ADC20D
md5: 6490c6b3c846e2195abc07cc124df3b1
name: ytbticket.exe
sha1: 91ffde21e116a0d7f0b522632268e102f0a6a847
sha256: fbfaf6b255e1e0aecffd51a1f98827b04adf979fc02a1fcefb823bb655028ae1
sha512: e4b5f07a4b947cc6aeaa73473e290a959a7c81f5b3e6945d72492be9d22a58d5940bb33e893ecf51b057233af99293e3652c3c37d35504044b3aa80f74006cd0
ssdeep: 49152:ecW4fituJPwGFZ9X+ez1/Dee+Sj+0nB2VQ:eX4ats5DdVh7N+Sj+G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: pdfreader2019
ProductVersion: 20.01
FileDescription: pdfreader2019 Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Trojanpws.Disbuk also known as:

DrWebTrojan.PWS.Stealer.27842
MicroWorld-eScanTrojan.GenericKD.33191745
FireEyeTrojan.GenericKD.33191745
CAT-QuickHealTrojanpws.Disbuk
ALYacTrojan.GenericKD.33191745
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 0054853f1 )
BitDefenderTrojan.GenericKD.33191745
K7GWSpyware ( 0054853f1 )
TrendMicroTROJ_GEN.R01FC0PBB20
BitDefenderThetaGen:NN.ZexaF.34090.Dm1@aK!FtUbj
CyrenW32/Trojan.WMMB-8331
APEXMalicious
GDataTrojan.GenericKD.33191745
KasperskyHEUR:Trojan-PSW.Win32.Disbuk.gen
AlibabaTrojanSpy:Win32/Socelars.c592ad1b
NANO-AntivirusTrojan.Win32.Stealer.guvczd
ViRobotTrojan.Win32.Z.Socelars.1892036
TencentWin32.Trojan-qqpass.Qqrob.Wops
Ad-AwareTrojan.GenericKD.33191745
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1045826
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan-Spy.Socelars (A)
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.1728101.susgen
AviraHEUR/AGEN.1045826
MAXmalware (ai score=88)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FA7741
AegisLabTrojan.Win32.Ekstak.4!e
ZoneAlarmHEUR:Trojan-PSW.Win32.Disbuk.gen
MicrosoftTrojan:Win32/Vigorf.A
AhnLab-V3Trojan/Win32.Disbuk.R302815
McAfeeDropper-FWS!6490C6B3C846
VBA32TrojanPSW.Disbuk
MalwarebytesSpyware.Socelars
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Spy.Socelars.S
TrendMicro-HouseCallTROJ_GEN.R01FC0PBB20
RisingSpyware.Socelars!8.EBE4 (CLOUD)
FortinetW32/Disbuk.S!tr
WebrootW32.Malware.gen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
Qihoo-360Win32/Trojan.PSW.3d5

How to remove Trojanpws.Disbuk?

Trojanpws.Disbuk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment