Backdoor

What is “Backdoor:Win32/Prosti.AG”?

Malware Removal

The Backdoor:Win32/Prosti.AG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Prosti.AG virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Prosti.AG?


File Info:

name: C00D637A7586FCB71D7E.mlw
path: /opt/CAPEv2/storage/binaries/3fd954dff678b49e9ff4abb5697ce2d679a0242c3bd170c45d16b2e799d05672
crc32: 1611118A
md5: c00d637a7586fcb71d7e5c31cbfdb7f9
sha1: 35a7376938d10f68f5b7f9a9b73911912afd1fe2
sha256: 3fd954dff678b49e9ff4abb5697ce2d679a0242c3bd170c45d16b2e799d05672
sha512: a9260871946f8a18cd03ee6ec5d583ef777177365ae6b7639cdc59c6eefd3a65e41f0fd5de78a4021b2f91bd8ead16aacd707ddc03d2a902cf58cb4414341923
ssdeep: 12288:ip/iN/mlVdtvrYeyZJf7kPK+iqBZn+D73iKHeGspqMFIHjEEN7vda:ipQ/6trYlvYPK+lqD73TeGspqMeHjLNg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154F4AE22F2E15837C1332A39DC1BA369982ABF512E2C65462BF55D5C8F3D7813C292D7
sha3_384: f7ac89aae48b6dc41c8fa40e393af79ccf98198af5af2264ae736cdba424648bf3e3aecafd3fedc74f9a93ade8b86e63
ep_bytes: 558bec83c4f0b84c014a00e8f866f6ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Prosti.AG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.ljsh
AVGWin32:Prosti-EF [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Adw.ScreenBlaze.BC2DE056
FireEyeGeneric.mg.c00d637a7586fcb7
CAT-QuickHealTrojan.Generic.15344
SkyhighBehavesLike.Win32.Generic.bh
McAfeeBackDoor-DUG.a
Cylanceunsafe
ZillyaDownloader.Delf.Win32.56759
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057116a1 )
AlibabaTrojanDownloader:Win32/Prosti.c9bc6090
K7GWTrojan ( 0057116a1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.F3DE8B7820
VirITTrojan.Win32.DownLoad.CHKH
SymantecHacktool.Rootkit
ESET-NOD32Win32/Adware.ScreenBlaze.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.Screenblaze-1
KasperskyTrojan-Downloader.Win32.Delf.uvk
BitDefenderGeneric.Adw.ScreenBlaze.BC2DE056
NANO-AntivirusTrojan.Win32.Delf.vsgy
AvastWin32:Prosti-EF [Trj]
TencentAdware.Win32.ScreenBlaze.aa
EmsisoftGeneric.Adw.ScreenBlaze.BC2DE056 (B)
F-SecureTrojan.TR/Dldr.Delf.uvk
DrWebTrojan.DownLoad.40151
VIPREGeneric.Adw.ScreenBlaze.BC2DE056
TrendMicroTROJ_DLOAD.SMMO
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Delf.qlw
VaristW32/ScreenBlaze.A.gen!Eldorado
AviraTR/Dldr.Delf.uvk
Antiy-AVLTrojan[Downloader]/Win32.Delf
KingsoftWin32.Troj.Undef.a
MicrosoftBackdoor:Win32/Prosti.AG
XcitiumTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
ArcabitGeneric.Adw.ScreenBlaze.BC2DE056
ViRobotTrojan.Win32.Downloader.758272.AED
ZoneAlarmTrojan-Downloader.Win32.Delf.uvk
GDataWin32.Trojan-Downloader.ScreenBlaze.A
GoogleDetected
AhnLab-V3Trojan/Win32.Scar.R38823
VBA32TrojanDownloader.Delf
ALYacGeneric.Adw.ScreenBlaze.BC2DE056
MalwarebytesScreenBlaze.Adware.Advertising.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_DLOAD.SMMO
RisingBackdoor.Win32.Prosti.xa (CLASSIC)
YandexTrojan.DL.Delf!2JuejRsfhm4
IkarusVirus.Downloader.Delf
MaxSecureTrojan.Malware.15169.susgen
FortinetW32/Delf.SCB!tr
Cybereasonmalicious.a7586f
alibabacloudTrojan[downloader]:Win/ScreenBlaze.AA

How to remove Backdoor:Win32/Prosti.AG?

Backdoor:Win32/Prosti.AG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment