Trojan

Should I remove “Trojan:Win32/Protob.B”?

Malware Removal

The Trojan:Win32/Protob.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Protob.B virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

www.shmyip.com

How to determine Trojan:Win32/Protob.B?


File Info:

crc32: 1C3CB45C
md5: 9f2f86f41044caacdc156dab963f281a
name: 9F2F86F41044CAACDC156DAB963F281A.mlw
sha1: c3ea775625b607d9f761db7d15ecf607403f0fe4
sha256: f11f2d4ff77a46677f36f4e86bde201e6e1112301e39063da3a08ca8c51ef074
sha512: d3748c507a5b32de1abf99f453edc4455d828502839f20aae01d4d5a884746434a36c2c7a7aeaab4cc59dff41ca6818b7ff0defeb0a2f7c3531348b1c122e5f9
ssdeep: 12288:zZ+KqH7zak7K0IXMBR6yrD7VORbCV/hWC:zji7zakIsR6yroRCV/hWC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
InternalName: STUBP
FileVersion: 1.00.0410
CompanyName: Microsoft
ProductName: Microsoft
ProductVersion: 1.00.0410
OriginalFilename: STUBP.exe

Trojan:Win32/Protob.B also known as:

K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader35.49932
CAT-QuickHealTrojan.NetbotaMF.S21116285
ALYacGen:Trojan.Heur.Nm0@f99zOoR
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.41044c
CyrenW32/Hupigon.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.OPL
APEXMalicious
AvastWin32:DropperX-gen [Drp]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.msvu
BitDefenderGen:Trojan.Heur.Nm0@f99zOoR
MicroWorld-eScanGen:Trojan.Heur.Nm0@f99zOoR
Ad-AwareGen:Trojan.Heur.Nm0@f99zOoR
SophosMal/Generic-S
BitDefenderThetaAI:Packer.DFC0442B1B
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.9f2f86f41044caac
EmsisoftGen:Trojan.Heur.Nm0@f99zOoR (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Protob.B
GDataGen:Trojan.Heur.Nm0@f99zOoR
AhnLab-V3Malware/Win32.RL_Generic.R298488
McAfeeArtemis!9F2F86F41044
MAXmalware (ai score=89)
VBA32SScope.Malware-Cryptor.VBCR.2841
PandaTrj/CI.A
IkarusTrojan.Win32.VB
AVGWin32:DropperX-gen [Drp]

How to remove Trojan:Win32/Protob.B?

Trojan:Win32/Protob.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment