Trojan

Trojan:Win32/Pronny.PA!MTB removal guide

Malware Removal

The Trojan:Win32/Pronny.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pronny.PA!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
ns1.musiczipz.com
ns1.musicmixa.net
ns1.musicmixa.org
ns1.musicmixb.co
ns1.musicmixc.com

How to determine Trojan:Win32/Pronny.PA!MTB?


File Info:

crc32: 347B1D59
md5: f064ea0d8414e391e4a79e8325ec0a90
name: F064EA0D8414E391E4A79E8325EC0A90.mlw
sha1: 42d2c05f54e473e2e0431bedd25d1c72c025972c
sha256: 9b89f9ed307f6be52d2452821e4cf9890982e6c70fefb5b426775d818f512b39
sha512: 5ad3744f81c2fe24cad1c99415dda94e8b6da2ff380bb85a297bd2430e0150c5d85adf31d8f70d61ee0fad39c229e6b334992d11a6b9cd206ed42473584a662e
ssdeep: 6144:Hstj9Ixh98UhaUodmDZ23wpJEoKHjWZLKBPvHIWM5n:FaUnZ2ApGvWpaPvsn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 6.09.0001
InternalName: xhlybsklzdgz
FileVersion: 6.09.0001
OriginalFilename: xhlybsklzdgz.exe
ProductName: qjrgyaif

Trojan:Win32/Pronny.PA!MTB also known as:

K7AntiVirusEmailWorm ( 0054d10f1 )
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.81
CynetMalicious (score: 100)
CAT-QuickHealTrojan.JorikVMF.S20641262
ALYacGen:Variant.Ursu.58764
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.503583
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2ffbc.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.d8414e
BaiduWin32.Worm.VB.be
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.AQW
APEXMalicious
AvastWin32:Pronny-K [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.ekip
BitDefenderGen:Variant.Ursu.58764
NANO-AntivirusTrojan.Win32.VB.coonpl
ViRobotWorm.Win32.A.WBNA.393216.D
MicroWorld-eScanGen:Variant.Ursu.58764
TencentWorm.Win32.Vobfus.n
Ad-AwareGen:Variant.Ursu.58764
SophosMal/Generic-R + Mal/VB-UY
ComodoWorm.Win32.Pronny.AK@4ogvoo
BitDefenderThetaGen:NN.ZevbaF.34266.ym0@amofCAoi
VIPRETrojan.Win32.Vobfus.paa (v)
TrendMicroTSPY_ZBOT.SMUK
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
FireEyeGeneric.mg.f064ea0d8414e391
EmsisoftGen:Variant.Ursu.58764 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Jorik.bmok
AviraTR/Vobfus.E.1
eGambitUnsafe.AI_Score_80%
Antiy-AVLTrojan/Generic.ASBOL.5
MicrosoftTrojan:Win32/Pronny.PA!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Ursu.58764
TACHYONTrojan/W32.Jorik.393216
AhnLab-V3Worm/Win32.WBNA.R120796
McAfeeVBObfus.dv
MAXmalware (ai score=84)
VBA32Malware-Cryptor.VB.gen
MalwarebytesMalware.AI.2050267932
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SMUK
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!wSksknNjkx0
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:Pronny-K [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Pronny.PA!MTB?

Trojan:Win32/Pronny.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment