Malware

PWS:Win32/Prast!rts removal instruction

Malware Removal

The PWS:Win32/Prast!rts is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Prast!rts virus can do?

  • Reads data out of its own binary image
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:Win32/Prast!rts?


File Info:

crc32: A900B234
md5: 2da4febcec740152ae3216a5aa32a24a
name: tat.exe
sha1: 21e40e615ba68fb55c127e0797359d80d13c610e
sha256: 6c906253d6572d6566f551f2323a5c9396e73e1e2c84cb86294d9679b6812d21
sha512: 0d3f44f6fa0d2e1bfaa40f0b6d22d4c625935f968e28bda0843445e498c71a7646a5061d0128de1280336cdcfa5c93decdc6c54b200d73992ddb11c32be3400d
ssdeep: 3072:RxuvPm0eFcbG/TqA7QvRBMGxGWfSDkjWsQ8UUIYi99NM5GpUM0iOX4g2+j8YD2Y:7OPmbL/kvRbbfYeWxJNMvodRhq0c0A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Prast!rts also known as:

CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic PWS.y
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
AlibabaVirus:Win32/HotKeysHook.f381ed65
K7GWPassword-Stealer ( 004c75551 )
K7AntiVirusPassword-Stealer ( 004c75551 )
BaiduWin32.Trojan.HotKeysHook.b
F-ProtW32/Keylogger.BQ
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Keylogger.HotKeysHook.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.HotKeysHook-2
NANO-AntivirusRiskware.Win32.Hatkeys.zrsxv
SUPERAntiSpywareHack.Tool/Gen-KeyLogger
TencentWin32.Virus.Agent.rhk
Endgamemalicious (high confidence)
ComodoWin32.Keylogger.HotKeysHook.A@zb8
F-SecureTrojan.TR/SPY.224391
Qihoo-360Win32/Trojan.Keylog.8d5
Invinceaheuristic
McAfee-GW-EditionRDN/Generic PWS.y
FortinetW32/PWS_y.G!tr
FireEyeGeneric.mg.2da4febcec740152
SophosGame Trainer (PUA)
IkarusVirus.Win32.Keylogger
CyrenW32/Keylogger.YBOK-3069
AviraTR/SPY.224391
MAXmalware (ai score=100)
MicrosoftPWS:Win32/Prast!rts
Acronissuspicious
ZonerTrojan.Win32.57300
RisingPUF.GameHack!1.B30C (CLASSIC)
YandexTrojanSpy.Agent!S1+w3CA7MBE
SentinelOneDFI – Suspicious PE
GDataWin32.Trojan.HotKeysHook.A
AVGWin32:Malware-gen
Cybereasonmalicious.15ba68
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecurenot-a-virus: Trojan.HotKeyHook

How to remove PWS:Win32/Prast!rts?

PWS:Win32/Prast!rts removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment