Backdoor

Backdoor:Win32/Protux.C!bit (file analysis)

Malware Removal

The Backdoor:Win32/Protux.C!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Protux.C!bit virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Protux.C!bit?


File Info:

name: 5648A29305E1262DA82A.mlw
path: /opt/CAPEv2/storage/binaries/f5afd0c4825dd040cfbd6617747a7156dda86ba846783d0174b7a433ffd6f505
crc32: ACBA1998
md5: 5648a29305e1262da82a333f519c0750
sha1: a0b3517aa3e18e17948f9d36ccfcb8c9ab292631
sha256: f5afd0c4825dd040cfbd6617747a7156dda86ba846783d0174b7a433ffd6f505
sha512: ee8400c7040673c56c3cec8de7666660c79f9b6bfb80ffba96a3bc24043559ce8dca8ddc34824ed0955ce377f77ca822c9e5c4e4ded8c576fc88dc76fcbfeab0
ssdeep: 24576:FmjTlHHKmMDsmonrtRtwGV5VIcA7PdDfw7BkfuDa/tY+Z0M1SeKcQ3:FmjZCsmonJRtwGzARU9nsjIe23
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1575533E1BC45ABB2CFE64772684F0852FF166D31C76BC16648603108F1B96F9D0B798A
sha3_384: ec6aca4714b8737d13f41976ffe26641a4dbc08430bd3c18aff7b44adef1a0882b760b917f84296ee9bf1dc89769d417
ep_bytes: 558bec6aff688031400068942a400064
timestamp: 2010-07-08 13:48:00

Version Info:

0: [No Data]

Backdoor:Win32/Protux.C!bit also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.94991
CAT-QuickHealBackdoor.Poison.18050
SkyhighBehavesLike.Win32.Generic.tc
ALYacTrojan.GenericKDZ.94991
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.94991
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0053eef51 )
BitDefenderTrojan.GenericKDZ.94991
K7GWTrojan ( 0053eef51 )
Cybereasonmalicious.aa3e18
BitDefenderThetaGen:NN.ZexaF.36792.v1Z@ay0RJ4c
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Protux.NAU
APEXMalicious
ClamAVWin.Trojan.Terminatorat-1
KasperskyTrojan-Dropper.Win32.Agent.sbra
NANO-AntivirusTrojan.Win32.SmlSDCW.bxogjo
RisingBackdoor.Protux!8.305D (TFE:5:tMETU0IEhID)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.MulDrop8.31902
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5648a29305e1262d
EmsisoftTrojan.GenericKDZ.94991 (B)
IkarusBackdoor.Win32.Protux
JiangminTrojanDropper.Agent.gfww
WebrootW32.Trojan.Gen
VaristW32/Protux.F.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Protux.C!bit
XcitiumTrojWare.Win32.Protux.NAS1@6ldg0s
ArcabitTrojan.Generic.D1730F
ZoneAlarmTrojan-Dropper.Win32.Agent.sbra
GDataTrojan.GenericKDZ.94991
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FQFT.C5522791
McAfeeTrojan-FQFT!5648A29305E1
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Tiggre
Cylanceunsafe
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10bf3997
YandexTrojan.DR.Agent!IAOg87T8BUA
SentinelOneStatic AI – Suspicious PE
FortinetW32/Protux.NAR!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Protux.C!bit?

Backdoor:Win32/Protux.C!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment