Trojan

Should I remove “Trojan:Win32/Pony”?

Malware Removal

The Trojan:Win32/Pony is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pony virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:Win32/Pony?


File Info:

name: 4A81B81A593C3DC74118.mlw
path: /opt/CAPEv2/storage/binaries/13f63060f1a061e9fc84cb18db1fa95aff4f9f799eec8d804bf7cf094123b74b
crc32: 1554F2F5
md5: 4a81b81a593c3dc7411837d8f288d452
sha1: 293b8d912f502c5678ac8bc57fbddde169f84010
sha256: 13f63060f1a061e9fc84cb18db1fa95aff4f9f799eec8d804bf7cf094123b74b
sha512: 2dd589cc573f05f1fd07997baa988aaf2df6f008dfc45ac4269015b6a1133124c0cff30efeb74fa09c9466795240c13fa489f8292849cee4bb65a01ff1eecf97
ssdeep: 1536:8KhXRaf8TVQMsV3/x9PT+pko+D2wAXufeS5OhOoA:8YAf8VQ7V3/x9PTGtTQej4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A104B591B155D88AE06B59B9DD5ED6F030A66C9DE0A4DA0F24937F0E32F3352109BE0F
sha3_384: dfafc5d84fce05cc857e0f609da0ca624d00ff54eb9c4f320aa76c34a454e5ce20e9f9a1a7b4a9b47a7e08a0674477e6
ep_bytes: 33db5053e82afeffff586003d8574756
timestamp: 2018-05-29 12:17:19

Version Info:

0: [No Data]

Trojan:Win32/Pony also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Dimnie.tpz0
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Spy.20945
MicroWorld-eScanTrojan.GenericKD.30899186
FireEyeGeneric.mg.4a81b81a593c3dc7
McAfeeGeneric.ayu
CylanceUnsafe
ZillyaTrojan.Dimnie.Win32.123
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00532f9c1 )
AlibabaTrojan:Win32/Dimnie.853e89b7
K7GWTrojan ( 00532f9c1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34646.lqW@aiNBhocG
VirITTrojan.Win32.Spy.BEZP
CyrenW32/Downloader.XNGF-0856
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Agent.SVO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Dimnie.vi
BitDefenderTrojan.GenericKD.30899186
NANO-AntivirusTrojan.Win32.Dimnie.fdycil
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.1149288f
Ad-AwareTrojan.GenericKD.30899186
SophosML/PE-A + Troj/BitPay-G
ComodoTrojWare.Win32.Dimnie.B@839wr4
VIPRETrojan.GenericKD.30899186
TrendMicroTROJ_FRS.VSN1EE18
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cm
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.30899186 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.LPZP0C
JiangminTrojan.Dimnie.dw
WebrootW32.Dimnie
GoogleDetected
AviraTR/Pony.S
MAXmalware (ai score=94)
Antiy-AVLTrojan/Generic.ASMalwS.45AB
KingsoftWin32.Troj.Dimnie.vi.(kcloud)
ViRobotTrojan.Win32.Agent.180224.DI
MicrosoftTrojan:Win32/Pony
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2550160
Acronissuspicious
VBA32Malware-Cryptor.General.3
ALYacTrojan.GenericKD.30899186
MalwarebytesMalware.AI.2113414198
TrendMicro-HouseCallTROJ_FRS.VSN1EE18
RisingTrojan.GenKryptik!8.AA55 (KTSE)
YandexTrojan.Dimnie!fO/TzbQ0QYE
IkarusTrojan.Inject
FortinetW32/GenKryptik.CBEM!tr
AVGWin32:Malware-gen
Cybereasonmalicious.a593c3
PandaTrj/WLT.D

How to remove Trojan:Win32/Pony?

Trojan:Win32/Pony removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment