Malware

Win32/AnMalPro.D potentially unwanted removal instruction

Malware Removal

The Win32/AnMalPro.D potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AnMalPro.D potentially unwanted virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/AnMalPro.D potentially unwanted?


File Info:

name: 430542D83F6010C58959.mlw
path: /opt/CAPEv2/storage/binaries/3e894e3f9fef8dec05798d3270bc28a3e45f0399cc48ddbfb636415e4e64bbc2
crc32: 8DBD842D
md5: 430542d83f6010c58959e48c1237c9d0
sha1: cfb3f2f7f60299960352ecec20b73017a8b5c388
sha256: 3e894e3f9fef8dec05798d3270bc28a3e45f0399cc48ddbfb636415e4e64bbc2
sha512: 7937bd64023bbb8c1b599b37543b4fac503cfe6f97802ec24547eb95fc143702c7215a5f034b18e8a15544ba5f7e896956d1953ed0308e325bd4ebb4909285c8
ssdeep: 24576:PUdW8giJHkafMPlsDbrwQO1hFGYJDr4c3ksxYy5T8biCS4OEcxU33M3s+efrNsmx:SW6yOMPlIbU51hFNJ/10sy0TCiCSlsMq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16155DF207AC1D033C16315720569D7B969BABA600B3149CFBBC82B7D5F306D2AA3D75B
sha3_384: 0a303277b394f2a57b84e6eacfc85c649d6c4f270311d77a4940944984fd7822392de8414e1a8e5626f9ccfd3cdbdb84
ep_bytes: e8f4af0000e979feffff8bff558bec83
timestamp: 2020-07-02 19:17:15

Version Info:

CompanyName: Advanced System Repair Inc.
FileDescription: Advanced System Repair Pro Service
FileVersion: 1.9.3.1
InternalName: Advanced System Repair Pro Service
LegalCopyright: Advanced System Repair, Inc.
OriginalFilename: Advanced System Repair Pro
ProductName: Advanced System Repair Pro
ProductVersion: 1.9.3.1
Translation: 0x0409 0x04b0

Win32/AnMalPro.D potentially unwanted also known as:

LionicTrojan.Win32.LssLogger.4!c
FireEyeGeneric.mg.430542d83f6010c5
CAT-QuickHealPUA.AgentRI.S16493609
MalwarebytesPUP.Optional.AdvancedSystemRepair
ZillyaTrojan.LssLogger.Win32.518
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/AnMalPro.D potentially unwanted
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.LssLogger.hmqycu
SUPERAntiSpywarePUP.ASR/Variant
DrWebProgram.Unwanted.4508
IkarusPUA.AnMalPro
GDataWin32.Application.ASRP.A
JiangminTrojanSpy.LssLogger.gz
WebrootW32.Adware.Gen
GoogleDetected
Antiy-AVLGrayWare/Win32.AnMalPro.d
VaristW32/S-aa21a356!Eldorado
VBA32BScope.TrojanSpy.LssLogger
Cylanceunsafe
MaxSecureTrojan.Malware.112054770.susgen
FortinetRiskware/AnMalPro
DeepInstinctMALICIOUS

How to remove Win32/AnMalPro.D potentially unwanted?

Win32/AnMalPro.D potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment