Trojan

Should I remove “Trojan:Win32/Danabot.DSK!MTB”?

Malware Removal

The Trojan:Win32/Danabot.DSK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Danabot.DSK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

biscayneinn.com
ip-api.com

How to determine Trojan:Win32/Danabot.DSK!MTB?


File Info:

crc32: 5B6185DF
md5: a7ffc700eca3323c9bbe5aa9bd15f759
name: 5.exe
sha1: 2b12646ae84801cb75122968b93f7b054ae0a33b
sha256: 7b5a9d6119e910f5c0441ae27293b0367718a4257062f29ec8ef27342a0b8de8
sha512: 88ef9267e1cc05795acca26eff2fc8672bfdc642a5ef5785dd33973e42550bd3a37a32e1e3f5a1762cfc45052ad4c3ab1bb360a488d25865912d54c1daba332d
ssdeep: 12288:bliqVYmkgDLybKOUfPQdTWAn0GICjeAA:bliqVFkgDLy2lnW6AniR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Danabot.DSK!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42845018
FireEyeGeneric.mg.a7ffc700eca3323c
SangforMalware
BitDefenderTrojan.GenericKD.42845018
K7GWTrojan ( 005626cd1 )
Cybereasonmalicious.ae8480
TrendMicroTROJ_GEN.R011C0DCF20
APEXMalicious
AvastWin32:DropperX-gen [Drp]
GDataTrojan.GenericKD.42845018
KasperskyTrojan.Win32.Chapak.ejvj
AlibabaTrojan:Win32/Chapak.6c998031
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Trojan.Chapak.Lpvj
Ad-AwareTrojan.GenericKD.42845018
EmsisoftTrojan.GenericKD.42845018 (B)
F-SecureTrojan.TR/AD.VidarStealer.apilz
DrWebTrojan.Siggen9.20761
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.BXWA-4085
AviraTR/AD.VidarStealer.apilz
Antiy-AVLTrojan/Win32.Chapak
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28DC35A
ZoneAlarmTrojan.Win32.Chapak.ejvj
MicrosoftTrojan:Win32/Danabot.DSK!MTB
Acronissuspicious
McAfeeArtemis!A7FFC700ECA3
MAXmalware (ai score=100)
MalwarebytesTrojan.Glupteba
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBXQ
TrendMicro-HouseCallTROJ_GEN.R011C0DCF20
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_72%
FortinetW32/Kryptik.HBXQ!tr
BitDefenderThetaGen:NN.ZexaF.34100.CuW@aCuFEwr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.451

How to remove Trojan:Win32/Danabot.DSK!MTB?

Trojan:Win32/Danabot.DSK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment