Backdoor

Backdoor:Win32/Prorat.AZ removal instruction

Malware Removal

The Backdoor:Win32/Prorat.AZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Prorat.AZ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:5110, 0.0.0.0:5112, 0.0.0.0:51100
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Attempts to stop active services
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
proend.ifrance.com
www.reza24.com
www.bing.com
aku.edu.tr
atauni.edu.tr
ege.edu.tr
ankara.edu.tr

How to determine Backdoor:Win32/Prorat.AZ?


File Info:

crc32: BE826987
md5: cb95a8fc3e50377b222be0289b90a0f4
name: services.exe
sha1: c3c60e075ec892eff9be1d79541d657c4e13093d
sha256: 31739ac593945cb154bb410bcaee57a2384c0aa69e097eca8c8c14244fb4f307
sha512: 4a68ba84b5c85d45a1a9161ac3a5a2d49be4ef9aa417ce7e1bd8b98169f0ea3ac1f9f1e9c9ec12ffb2487286cfebbb877a3970b0ef34e908b7e7d4e7afa9a91d
ssdeep: 6144:YRqmpp+amNOGokzLyM9tsLAitQo6tzOKkzIt8gKyfjxfR9D2j4y1QPf:cqmpplpGoGL3etQoMiXM8gxf/Sj4yQf
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Backdoor:Win32/Prorat.AZ also known as:

BkavW32.DownloadProratA.Trojan
DrWebTrojan.MulDrop.2765
MicroWorld-eScanTrojan.Generic.7807554
FireEyeGeneric.mg.cb95a8fc3e50377b
CAT-QuickHealBackdoor.Prorat.AZ2
McAfeeArtemis!CB95A8FC3E50
CylanceUnsafe
VIPRETrojan.Win32.Small.E (v)
SangforMalware
K7AntiVirusTrojan ( 00544ddf1 )
BitDefenderTrojan.Generic.7807554
K7GWTrojan ( 00544ddf1 )
Cybereasonmalicious.c3e503
TrendMicroTROJ_DROPPER.CKK
BitDefenderThetaAI:Packer.AB2918CC1D
F-ProtW32/ProratP.G
SymantecTrojan Horse
TotalDefenseWin32/SillyDl.SR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Prorat-11
GDataTrojan.Generic.7807554
KasperskyTrojan-Dropper.Win32.Agent.bczn
AlibabaBackdoor:Win32/Prorat.5681b19d
NANO-AntivirusTrojan.Win32.Small.gnhm
ViRobotDropper.Small.372947
AegisLabTrojan.Win32.Prorat.kYMr
AvastWin32:Small-BHA [Trj]
RisingBackdoor.Win32.ProRat.i (CLASSIC)
Ad-AwareTrojan.Generic.7807554
EmsisoftTrojan.Generic.7807554 (B)
ComodoBackdoor.Win32.Prorat.~RJ@aatpw
F-SecureBackdoor.BDS/Prorat.19.N
BaiduWin32.Backdoor.Prorat.e
ZillyaDropper.Agent.Win32.103592
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
CMCTrojan-Dropper.Win32.Small!O
SophosTroj/Prorat-O
IkarusTrojan-Dropper.Agent
CyrenW32/ProratP.G
JiangminTrojanDropper.Small.bjq
WebrootW32.Malware.gen
AviraBDS/Prorat.19.N
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.VB.aoi
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D772242
SUPERAntiSpywareTrojan.Agent/Gen-Small
ZoneAlarmTrojan-Dropper.Win32.Agent.bczn
MicrosoftBackdoor:Win32/Prorat.AZ
AhnLab-V3Dropper/Win32.Agent.R10217
Acronissuspicious
VBA32TrojanDropper.Agent
ALYacTrojan.Generic.7807554
ESET-NOD32Win32/Prorat
TrendMicro-HouseCallTROJ_DROPPER.CKK
TencentMalware.Win32.Gencirc.10b0771d
YandexTrojan.DR.Small.AVF1
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Small.RC!tr
AVGWin32:Small-BHA [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Malware.Radar05.Gen

How to remove Backdoor:Win32/Prorat.AZ?

Backdoor:Win32/Prorat.AZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment