Backdoor

Backdoor:Win32/ProxyBot.C removal tips

Malware Removal

The Backdoor:Win32/ProxyBot.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/ProxyBot.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/ProxyBot.C?


File Info:

name: 7C1D6A995F8593EAE393.mlw
path: /opt/CAPEv2/storage/binaries/b4cc8f5837c1694f91aa6df22ec982a4d6ab4df7fec2777c7f2d40d9941f6274
crc32: 5EA32108
md5: 7c1d6a995f8593eae393afd9135d6923
sha1: 0b75213687a5616b6e4506db2aaf8387f4e7e378
sha256: b4cc8f5837c1694f91aa6df22ec982a4d6ab4df7fec2777c7f2d40d9941f6274
sha512: 2d401b094a72555854a26261bfdc0f293b75f9c99fc9d5cee1abe5c81265c585065e9a404cd6b8bc700704668b8b05ea71c0c80129fedf92824562893be0c7e7
ssdeep: 1536:NZXEj6ccjKRElKQ6iVCYUiHY5pYL4lbG/c4hp5ijTJpEZV2Bwz7u+J7lBKo6jaL:N0FAlJ1E5pZbG/BhpwjjeVu8yiTv6c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182B3DFC0669D7CD6CCBC727A418ECB0F536A9676A784CECE3084A692F2477E64036D74
sha3_384: ecb3e33cd094e0fe53f3b2affaa02d8c27759a640b2eef1fdb139a888e14cfe2f1c0492cdf2b42dd5791964fae96c11d
ep_bytes: 558bec81ec0404000068323c0110683a
timestamp: 2000-08-18 11:38:52

Version Info:

0: [No Data]

Backdoor:Win32/ProxyBot.C also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Sirefef.6788
ClamAVWin.Trojan.Agent-934516
FireEyeGeneric.mg.7c1d6a995f8593ea
ALYacGen:Variant.Sirefef.6788
CylanceUnsafe
ZillyaTrojan.Agent.Win32.191741
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 003b254a1 )
K7GWTrojan ( 003b254a1 )
Cybereasonmalicious.95f859
VirITTrojan.Win32.Proxy.ARJA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.SXK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.abusa
BitDefenderGen:Variant.Sirefef.6788
NANO-AntivirusTrojan.Win32.Agent.chuavv
SUPERAntiSpywareTrojan.Agent/Gen-SolidC
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Sirefef.6788
SophosML/PE-A + Mal/Rorpian-D
DrWebTrojan.Packed.18626
VIPREGen:Variant.Sirefef.6788
TrendMicroTROJ_KRYPTK.SMUH
McAfee-GW-EditionPWS-Spyeye.gl
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Sirefef.6788 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Sirefef.6788
JiangminTrojanProxy.Agent.con
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.2D
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftBackdoor:Win32/ProxyBot.C
GoogleDetected
AhnLab-V3Trojan/Win32.SpyEye.R64363
McAfeePWS-Spyeye.gl
VBA32BScope.Trojan.Agent
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_KRYPTK.SMUH
RisingWorm.Cridex!8.BB3 (TFE:2:ofS6JduiSkF)
YandexTrojan.PR.Agent!nmcWpdiNB0M
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rorpian.C!tr
BitDefenderThetaGen:NN.ZexaF.34646.hCW@a4I!ksii
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/ProxyBot.C?

Backdoor:Win32/ProxyBot.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment