Trojan

Trojan:Win32/Pronny!pz information

Malware Removal

The Trojan:Win32/Pronny!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pronny!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Pronny!pz?


File Info:

name: CFF88AA9F6DFE1DC9B10.mlw
path: /opt/CAPEv2/storage/binaries/43a92bc200b37ff8884aad2051d93089fb78748e934b9f8f2a47d5005b1d8adb
crc32: AA421E4D
md5: cff88aa9f6dfe1dc9b100871c47eabf4
sha1: 82d690cb2f3632cdcf2929565a50bcec58e2ed70
sha256: 43a92bc200b37ff8884aad2051d93089fb78748e934b9f8f2a47d5005b1d8adb
sha512: 8d335c77457c16db0dd3100a49d17133e4aa5ee77819a7039736cea23d5e6a185ca81a042c4434e715ae88a09277f9261682ea5f6f98d1326cdec3b9ef059253
ssdeep: 6144:n57Wk3vnS/Gi+YdQEp9szHR8uBAoE0EOIp5Jlt:pWk3vnS/Gi+YdQEp9szHR8uBAotSft
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C434C63DB2A0A73EE425D6F52C998399005EAD3615D4E84BF7C22B1976F0DE38231793
sha3_384: 5402da0946e6c2359e019d51fad9474415747cf85a4a8c24e902c3313e9259844de19afc63a9f391a2c0681881097924
ep_bytes: 68fc4a4000e8eeffffff000000000000
timestamp: 2012-02-06 20:53:01

Version Info:

Translation: 0x0409 0x04b0
ProductName: tBFHEI
FileVersion: 1.00
ProductVersion: 1.00
InternalName: mGqQOH
OriginalFilename: mGqQOH.exe

Trojan:Win32/Pronny!pz also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lIOe
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Chinky.7
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.cff88aa9f6dfe1dc
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.Chinky.7
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1434857
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff7.None
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36744.om0@aaorsCji
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ARU
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dfdb
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.WBNA.csfhkf
ViRobotWorm.Win32.A.WBNA.241664.JY
AvastWin32:VB-ABBN [Trj]
TACHYONWorm/W32.Vobfus.241664.B
SophosMal/ZboCheMan-B
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Chinky.70993
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Chinky.7 (B)
IkarusTrojan.Win32.Otran
GDataGen:Variant.Chinky.7
GoogleDetected
AviraTR/Chinky.70993
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Chinky.7
ZoneAlarmWorm.Win32.Vobfus.dfdb
MicrosoftTrojan:Win32/Pronny!pz
VaristW32/Vobfus.AI.gen!Eldorado
AhnLab-V3Worm/Win32.WBNA.R20484
Acronissuspicious
McAfeeVBObfus.df
MAXmalware (ai score=85)
VBA32BScope.Malware-Cryptor.VBCR.7212
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!Gd8K7rB2haM
SentinelOneStatic AI – Malicious PE
FortinetW32/VB.AZGU!tr
AVGWin32:VB-ABBN [Trj]
Cybereasonmalicious.b2f363
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Pronny!pz?

Trojan:Win32/Pronny!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment