Backdoor

Backdoor:Win32/Prosti.R removal instruction

Malware Removal

The Backdoor:Win32/Prosti.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Prosti.R virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Prosti.R?


File Info:

name: 4B0A24EA8B568CFDEC73.mlw
path: /opt/CAPEv2/storage/binaries/a65000a034c353db36aa853d83ddd7919d3f7fa68b83472d74a725eaf52c8ba6
crc32: 873585EC
md5: 4b0a24ea8b568cfdec73607df59d2d73
sha1: 97adaf0767e59e04a8fa2a8692429529b5a35916
sha256: a65000a034c353db36aa853d83ddd7919d3f7fa68b83472d74a725eaf52c8ba6
sha512: f6294fab21cc3e1062eef96c42199f0dea900bd5ae5d5448c11760d0d68d7be1d4008c2e91b77a133065400f7a5aefc1f417536b215ea2909c571734a4b86abc
ssdeep: 1536:LRx2+sTeldtW+B1plG0DC7fuXrkh6NkggCH3EPEXkS1T1Xptej7yR0sF1cPu:dxEelzBtG8CTerg6NkqH3YCtn+7tsbc2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C730283D7B1BE6FE0C85879C31D6570807F768280B9DF0DC6C4969AEA5A79590C02AF
sha3_384: fdeea6b4364dc7ec7d55b7b079185ccedd2de681a9e4d0e4bd9ec6c6bffe9efa7145d583718e76f869c812b357605a98
ep_bytes: 6850b04400e80000000083c404e80000
timestamp: 2008-01-22 08:36:45

Version Info:

0: [No Data]

Backdoor:Win32/Prosti.R also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanGeneric.Malware.FLBEn!dld!.FB9C4C7E
ClamAVWin.Trojan.Packed-74
FireEyeGeneric.mg.4b0a24ea8b568cfd
ALYacGeneric.Malware.FLBEn!dld!.FB9C4C7E
CylanceUnsafe
VIPREGeneric.Malware.FLBEn!dld!.FB9C4C7E
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005257651 )
AlibabaBackdoor:Win32/Prosti.5dac6e1f
K7GWTrojan ( 005257651 )
Cybereasonmalicious.a8b568
CyrenW32/Threat-IKNP.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ZonerProbably Heur.ExeHeaderP
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Prosti.ek
BitDefenderGeneric.Malware.FLBEn!dld!.FB9C4C7E
NANO-AntivirusTrojan.Win32.OnLineGames.npxz
AvastWin32:RPoly [Cryp]
TencentWin32.Backdoor.Prosti.Iflw
Ad-AwareGeneric.Malware.FLBEn!dld!.FB9C4C7E
EmsisoftGeneric.Malware.FLBEn!dld!.FB9C4C7E (B)
ComodoPacked.Win32.Klone.~KA@1jbcwy
DrWebBackDoor.IRC.Sdbot.18537
ZillyaTrojan.OnLineGames.Win32.45836
TrendMicroMal_Pai-9
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-BN
SentinelOneStatic AI – Malicious PE
GDataGeneric.Malware.FLBEn!dld!.FB9C4C7E
JiangminTrojan/PSW.OnLineGames.ajsn
WebrootW32.Prosti.Gen
AviraTR/Crypt.NSPM.Gen
Antiy-AVLTrojan/Generic.ASMalwFH.12
ArcabitGeneric.Malware.FLBEn!dld!.FB9C4C7E
ZoneAlarmBackdoor.Win32.Prosti.ek
MicrosoftBackdoor:Win32/Prosti.R
GoogleDetected
AhnLab-V3Win32/RPCrypt.Suspicious
McAfeeArtemis!4B0A24EA8B56
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Delf
MalwarebytesTrojan.MalPack.NSPack
TrendMicro-HouseCallMal_Pai-9
RisingBackdoor.Hupigon!8.B57 (TFE:1:p2w2lVEPLaI)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PEMask.A!tr
BitDefenderThetaAI:Packer.81ECDCFC1D
AVGWin32:RPoly [Cryp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor:Win32/Prosti.R?

Backdoor:Win32/Prosti.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment