Backdoor

Should I remove “Backdoor:Win32/ProxyBot.D”?

Malware Removal

The Backdoor:Win32/ProxyBot.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/ProxyBot.D virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Backdoor:Win32/ProxyBot.D?


File Info:

name: 401112FAC421DDF05A4E.mlw
path: /opt/CAPEv2/storage/binaries/bee7ad056cd5cba31de6f0491d801287ab2920aa2c9bd822df456de92e8ad29a
crc32: 5457CAFD
md5: 401112fac421ddf05a4ed95a7cda4c36
sha1: 0af77723b2b18e35a602dfecff68cf11a44bf94d
sha256: bee7ad056cd5cba31de6f0491d801287ab2920aa2c9bd822df456de92e8ad29a
sha512: 98df8cc4351b3738cbaa0fbc1835e2a1e73000c5d722550d2c5b085f1a962615cfa3aa4f921428f3acd342bc1e202332c54d7a0e6e3defcd90480726948efb55
ssdeep: 6144:N7nrKS24n8Fr/VbWGE8wLXfrSSbb12SxhUnxgwGmlYjFmTnwbP:xrKSBUrAGEhb11/Uxrl8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E54422499D1D985DFF5C13BF031430E8A005AE3E1428A1579667BFEE24B43C613BE7A6
sha3_384: e1e7cf16f9d25dc5936e04d135fd2fb97f1634711e039fc6d13bbd04718063c83c9cf1d3b78b7df0a2291d5397e3b3ec
ep_bytes: 83e2ff00e528e54e4690e81400000080
timestamp: 2010-11-11 13:17:00

Version Info:

0: [No Data]

Backdoor:Win32/ProxyBot.D also known as:

BkavW32.Vetor.PE
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.CIXS
FireEyeGeneric.mg.401112fac421ddf0
CAT-QuickHealW32.Virut.G
McAfeeW32/Virut.n.gen
MalwarebytesMalware.Heuristic.1003
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.ac421d
BaiduWin32.Virus.Virut.gen
VirITWin32.Scribble.E
CyrenW32/Virut.AI!Generic
Elasticmalicious (high confidence)
ESET-NOD32Win32/Virut.NBP
APEXMalicious
ClamAVWin.Trojan.Scar-6326
KasperskyVirus.Win32.Virut.ce
BitDefenderTrojan.Agent.CIXS
NANO-AntivirusVirus.Win32.Virut.hpeg
AvastWin32:Vitro [Inf]
RisingVirus.Virut!1.A08B (CLASSIC)
Ad-AwareTrojan.Agent.CIXS
EmsisoftTrojan.Agent.CIXS (B)
ComodoVirus.Win32.Virut.Ce@1fy3nv
F-SecureMalware.W32/Virut.Gen
DrWebWin32.Virut.56
VIPRETrojan.Agent.CIXS
TrendMicroPE_VIRUX.E
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
Trapminemalicious.high.ml.score
SophosML/PE-A + W32/Scribble-B
IkarusBackdoor.Win32.ProxyBot
GDataTrojan.Agent.CIXS
JiangminWin32/Virut.bn
WebrootW32.Virut.Gen
GoogleDetected
AviraW32/Virut.Gen
MAXmalware (ai score=84)
ArcabitTrojan.Agent.CIXS
ViRobotWin32.Virut.Gen.C
ZoneAlarmVirus.Win32.Virut.ce
MicrosoftBackdoor:Win32/ProxyBot.D
CynetMalicious (score: 100)
AhnLab-V3Win32/Virut.F
BitDefenderThetaAI:FileInfector.C9457D4313
ALYacTrojan.Agent.CIXS
TACHYONVirus/W32.Virut.Gen
VBA32Virus.Virut.06
CylanceUnsafe
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_VIRUX.E
TencentVirus.Win32.Virut.tt
YandexTrojan.GenAsa!N86zHkHB+vI
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Virut.CE
FortinetW32/Virut.CE
AVGWin32:Vitro [Inf]
PandaW32/Sality.AO
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor:Win32/ProxyBot.D?

Backdoor:Win32/ProxyBot.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment