Trojan

How to remove “Trojan:Win32/Disqui”?

Malware Removal

The Trojan:Win32/Disqui is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Disqui virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Disqui?


File Info:

crc32: 619557B2
md5: f08e80fa6b02901d8bb08ea82ad48eeb
name: F08E80FA6B02901D8BB08EA82AD48EEB.mlw
sha1: bd1c95fbfdd848fa6219b01eb75afb8aa4cf7a2d
sha256: d7f14de7462c9dc779839eef029dc6d8975910a88f5375f7ca3cf2b8cadf73ee
sha512: 412773d90fb76e8d223ec32415e4d2671bd36cfb9e0fb18408fe0fda03893e1bb331b6b351841f9d8d4e7c7b400ba4ae48b800be29508704f1dd0be6d35c4f48
ssdeep: 12288:gjpF51zhTXns1L+DTURQ6tPm5Y9d85OVeQqo2b2o8ySd6a+DxJ:yrDSRKY9d85OVQo2r8nQn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. Compass
InternalName: Deepest Order
FileVersion: 4.3.3.3
CompanyName: Compass
FileDescription: Diskcpy Quickest Jci
LegalTrademarks: Copyright xa9. All rights reserved. Compass
ProductName: Deepest Order
ProductVersion: 4.3.3.3
PrivateBuild: 4.3.3.3
OriginalFilename: Deepest Order
Translation: 0x0409 0x04b0

Trojan:Win32/Disqui also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Ryuk.5
FireEyeGeneric.mg.f08e80fa6b02901d
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeRDN/Generic PWS.mz
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zbot.l!c
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0051fb6b1 )
BitDefenderGen:Variant.Ransom.Ryuk.5
K7GWSpyware ( 0051fb6b1 )
Cybereasonmalicious.a6b029
BitDefenderThetaGen:NN.ZexaF.34590.Fu0@aq@4Frbi
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-6508023-0
KasperskyHEUR:Trojan-Spy.Win32.Zbot.gen
AlibabaTrojanSpy:Win32/Disqui.595c5816
NANO-AntivirusTrojan.Win32.Yakes.fahjgl
ViRobotTrojan.Win32.Agent.516096.AB
RisingSpyware.Zbot!8.16B (CLOUD)
Ad-AwareGen:Variant.Ransom.Ryuk.5
EmsisoftGen:Variant.Ransom.Ryuk.5 (B)
ComodoMalware@#3bx2l1yr8b3b8
F-SecureTrojan.TR/AD.PandaBanker.Y
DrWebTrojan.Siggen7.47858
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
SophosMal/Generic-R + Troj/Zbot-MBD
IkarusTrojan-Spy.Agent
GDataGen:Variant.Ransom.Ryuk.5
JiangminTrojan.Yakes.zlk
MaxSecureTrojan.Malware.12308549.susgen
AviraTR/AD.PandaBanker.Y
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Ransom.Ryuk.5
ZoneAlarmHEUR:Trojan-Spy.Win32.Zbot.gen
MicrosoftTrojan:Win32/Disqui
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Disqui.C2467763
Acronissuspicious
ALYacSpyware.Banker.panda
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
ZonerTrojan.Win32.66552
ESET-NOD32Win32/Spy.Zbot.ADC
TrendMicro-HouseCallTSPY_ZBOT.TIBAEBO
TencentWin32.Trojan-spy.Zbot.Ebgo
YandexTrojan.Yakes!T140tjuWRUU
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_94%
FortinetW32/Kryptik.GFRC!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.PandaBanker.HgIASOgA

How to remove Trojan:Win32/Disqui?

Trojan:Win32/Disqui removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment