Trojan

TrojanProxy:Win32/Potukorp.A removal guide

Malware Removal

The TrojanProxy:Win32/Potukorp.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanProxy:Win32/Potukorp.A virus can do?

  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com

How to determine TrojanProxy:Win32/Potukorp.A?


File Info:

crc32: 8B048343
md5: 6070e36e878d7cef2e637a52f9fb5522
name: 6070E36E878D7CEF2E637A52F9FB5522.mlw
sha1: 2919e0a5a071d031fc0a572a23f397bdd78365dd
sha256: 48fadea8e3e9bcf803ffba3b3c78c87a0ea3adebe60036aadde10d26ce230b03
sha512: 8bb2afa630bd555ee09aff1b5baf7a32be42e570fe9f2f3424a850547c42f27b345c5209b67bac755958d68bacfb470541ae50927fc19dcc6460ddd465edc565
ssdeep: 1536:DtdbxW0J3ho0pFIPCZQ3L3FdYrSPRBIYQgvluCOaDjMsI3eSOkSLlD23Wo8bLOM:J0rT2mNLOMK6UtofecYg
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: (C) Microsoft Corporation. All rights reserved.
InternalName: SHLWAPI
FileVersion: 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.5912
FileDescription: Shell Light-weight Utility Library
OriginalFilename: SHLWAPI.DLL
Translation: 0x0804 0x04b0

TrojanProxy:Win32/Potukorp.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.Hosts.44548
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.111863
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.e878d7
CyrenW32/Busky.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Qhost.Banker.OM
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tiggre-9845940-0
BitDefenderGen:Variant.Fugrafa.111863
NANO-AntivirusTrojan.Win32.FKM.fastzc
MicroWorld-eScanGen:Variant.Fugrafa.111863
TencentWin32.Trojan.Crypt.Wmiq
Ad-AwareGen:Variant.Fugrafa.111863
SophosMal/Generic-S
ComodoTrojWare.Win32.Banker.OM@5616y6
BitDefenderThetaGen:NN.ZexaF.34692.nm0@aarV6Kjb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dz
FireEyeGeneric.mg.6070e36e878d7cef
EmsisoftGen:Variant.Fugrafa.111863 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.260E818
MicrosoftTrojanProxy:Win32/Potukorp.A
ArcabitTrojan.Fugrafa.D1B4F7
GDataGen:Variant.Fugrafa.111863
Acronissuspicious
McAfeeGenericRXCF-BH!6070E36E878D
MAXmalware (ai score=99)
VBA32BScope.TrojanRansom.Foreign
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazpJyc0b39AWKpTVi+BEJxP4)
YandexTrojan.GenAsa!v5M7W+RdsEI
IkarusVirus.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.191810!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove TrojanProxy:Win32/Potukorp.A?

TrojanProxy:Win32/Potukorp.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment