Trojan

Trojan:Win32/Magania.DSK!MTB removal tips

Malware Removal

The Trojan:Win32/Magania.DSK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Magania.DSK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Magania.DSK!MTB?


File Info:

crc32: 7B97188C
md5: 324fa74027bd02c3615c7fbef11152cd
name: 324FA74027BD02C3615C7FBEF11152CD.mlw
sha1: 3da3748724f4e880f7835ef69721fa60a6dd2c79
sha256: 5b515b64c508f82534e8741922919a38033e5f382a8dda783d1aa83e480fe96f
sha512: 66aa403341d909bd7a44a2b337ffe38fead0c41408cc3638e09277f7359bc3db876524280ba566bd02b1a0eb0984156a3b11702ad46fa469a14f4df80f2e76c8
ssdeep: 768:WtrYLOAb8u1n/DqPzR8lSvXpvQTf2z5JXhAiycIdn:qcLOs8In/mpfgI5JXpycIdn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: PNSP
FileVersion: 5.0.17822.0
CompanyName: PSNR NTP Host Company
PrivateBuild:
LegalTrademarks: PSNR NTP Space Provider
Comments:
ProductName: PNSP
SpecialBuild:
ProductVersion: 5.0.17822.0
FileDescription: PSNR NTP Space Provider
OriginalFilename: PNSP
Translation: 0x0804 0x04b0

Trojan:Win32/Magania.DSK!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.285455
FireEyeGeneric.mg.324fa74027bd02c3
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FNTV!324FA74027BD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0053266f1 )
BitDefenderGen:Variant.Zusy.285455
K7GWTrojan ( 0053266f1 )
Cybereasonmalicious.027bd0
BitDefenderThetaGen:NN.ZexaF.34804.dq1@a0FdU8lH
CyrenW32/OnlineGames.LJ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/ServStart.OP
AvastWin32:Malware-gen
ClamAVWin.Malware.Magania-9809007-0
KasperskyTrojan-GameThief.Win32.Magania.uhsl
AlibabaTrojan:Win32/Magania.4ee79a0e
NANO-AntivirusTrojan.Win32.Magania.erpsaa
AegisLabTrojan.Win32.Magania.tr3J
TencentMalware.Win32.Gencirc.10b07a0b
Ad-AwareGen:Variant.Zusy.285455
EmsisoftGen:Variant.Zusy.285455 (B)
ComodoTrojWare.Win32.ServStart.OP@816o3k
F-SecureHeuristic.HEUR/AGEN.1134988
DrWebTrojan.DownLoader25.16681
ZillyaTrojan.Magania.Win32.71342
McAfee-GW-EditionBehavesLike.Win32.Dropper.pm
SentinelOneStatic AI – Malicious PE – Spyware
SophosMal/Generic-S + Troj/AutoG-CP
APEXMalicious
JiangminTrojan.Generic.bexvc
AviraHEUR/AGEN.1134988
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Magania.DSK!MTB
ArcabitTrojan.Zusy.D45B0F
AhnLab-V3Trojan/Win32.Magania.R207086
ZoneAlarmTrojan-GameThief.Win32.Magania.uhsl
GDataGen:Variant.Zusy.285455
CynetMalicious (score: 100)
Acronissuspicious
VBA32TrojanPSW.Magania
ALYacGen:Variant.Zusy.285455
MalwarebytesTrojan.ServStart
PandaTrj/Genetic.gen
ZonerTrojan.Win32.73013
RisingTrojan.ServStart!1.B6AB (CLASSIC)
YandexTrojan.GenAsa!jLB/MfRyLbE
IkarusBackdoor.Win32.Inject
eGambitUnsafe.AI_Score_99%
FortinetW32/Magania.UHSL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.GameThief.201

How to remove Trojan:Win32/Magania.DSK!MTB?

Trojan:Win32/Magania.DSK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment