Backdoor

Backdoor:Win32/Protos.A removal guide

Malware Removal

The Backdoor:Win32/Protos.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Protos.A virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Protos.A?


File Info:

crc32: EA305F83
md5: b8dcb952c377e757e5a5ab6432c49e96
name: pack_de_ropa.exe
sha1: b9de1aa2f1b3a09377dc4f3f4acb3690ea665eb0
sha256: df9fbf384a33485680fd5aee02cd23cdefee93fdb84cfe8e941de594eac9f7b0
sha512: a973d21fe5a4a015761970cffe535deaa3b599e7a4a9da0c4b557741d95e44e3a522f9e27436041aed4d577a8cf259dd6c70c4661fc52fd54927c7bec38783a4
ssdeep: 6144:J757qDiizlq2FCHpesDXF7WOZoaisJHWbMqpdT93o8qFW1APP6ldsRVwuXvUk8CD:NNqDu/px1Ws9Wbtb933APxv599bf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Protos.A also known as:

BkavW32.LeutiscoLTAA.Trojan
DrWebTrojan.Siggen7.20605
MicroWorld-eScanTrojan.Agent.Delf.RVA
FireEyeGeneric.mg.b8dcb952c377e757
CAT-QuickHealBackdoor.Agent.17414
Qihoo-360HEUR/QVM05.1.1375.Malware.Gen
McAfeeGenericRXES-CT!B8DCB952C377
ALYacTrojan.Agent.Delf.RVA
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055e3e61 )
BitDefenderTrojan.Agent.Delf.RVA
K7GWTrojan ( 0055e3e61 )
Cybereasonmalicious.2c377e
Invinceaheuristic
BitDefenderThetaAI:Packer.FB39425E17
F-ProtW32/MalwareS.BIKW
SymantecInfostealer
TotalDefenseWin32/Tnega.fELLHMC
APEXMalicious
AvastWin32:Agent-AQMU [Trj]
ClamAVWin.Trojan.Agent-335714
GDataTrojan.Agent.Delf.RVA
KasperskyBackdoor.Win32.Agent.awye
NANO-AntivirusTrojan.Win32.Agent.cekuh
ViRobotBackdoor.Win32.A.Agent.377856
TencentMalware.Win32.Gencirc.10b3d0cd
Endgamemalicious (high confidence)
SophosMal/Bckdr-U
F-SecureBackdoor:W32/Protos.A
BaiduWin32.Backdoor.Delf.as
ZillyaBackdoor.Agent.Win32.22116
TrendMicroBKDR_AGENT.SMP2
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fh
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.Agent!O
EmsisoftTrojan.Agent.Delf.RVA (B)
IkarusBackdoor.Win32.Nosrawec
CyrenW32/Risk.CJJP-7449
JiangminBackdoor/Agent.clbp
WebrootW32.Backdoor.Gen
AviraDR/Delphi.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Agent
ArcabitTrojan.Agent.Delf.RVA
SUPERAntiSpywareTrojan.Agent/Gen-Infostealer
ZoneAlarmBackdoor.Win32.Agent.awye
MicrosoftBackdoor:Win32/Protos.A
TACHYONBackdoor/W32.DP-Agent.364032
AhnLab-V3Trojan/Win32.Agent.C65173
VBA32BScope.Trojan.MulDrop
MAXmalware (ai score=83)
Ad-AwareTrojan.Agent.Delf.RVA
MalwarebytesBackdoor.Bot
PandaGeneric Malware
ESET-NOD32Win32/Delf.NZL
TrendMicro-HouseCallBKDR_AGENT.SMP2
RisingTrojan.PSW.Win32.QQPass.fgd (RDMK:cmRtazqHHLlTW5SsYz0K7tNxOa29)
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.AWYE!tr
AVGWin32:Agent-AQMU [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.1530823.susgen

How to remove Backdoor:Win32/Protos.A?

Backdoor:Win32/Protos.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment