Malware

Win32/Pronny.CG removal

Malware Removal

The Win32/Pronny.CG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Pronny.CG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Pronny.CG?


File Info:

name: 4F9405C2ED4E0B908F51.mlw
path: /opt/CAPEv2/storage/binaries/62f6ea1244fb15e1037a9dd72f0e6cb13dd43945788f8f7cb4c71140124e5649
crc32: 46A0C104
md5: 4f9405c2ed4e0b908f517e6baec94e57
sha1: 20f427253d0f1e3cd2caa756e884ec81c9ffafe9
sha256: 62f6ea1244fb15e1037a9dd72f0e6cb13dd43945788f8f7cb4c71140124e5649
sha512: 83cc0e97f79a559bbff503b6dc190b2a393deaabe4f544d71ff460940792e027b0110b54ec2f6ffbafa6372c79468c7da0fac8703a9e5b22d33e0b3ef3d95b23
ssdeep: 3072:yoHcIjEfW+zx3ad1bCUkZArSnXBUlyiaCeXWnUeg:2cMV3ad1bCUkZArSnXBUlyiaCIh5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18FD3A22BBF9E9491E50911386EF3C7F51666AC1A7E07510B6B143B6EE9B3F001C5CA23
sha3_384: 1ee1fe204aaff09b1e38f6384a48e71d1a26c47885f18ff4e10fad27483b7d2edee933545047f00815fc2bd159f0a507
ep_bytes: 68c4124000e8eeffffff000000000000
timestamp: 2012-08-10 05:07:40

Version Info:

Translation: 0x0409 0x04b0
Comments: Prehydration misapprehensively Bushrope
CompanyName: Prehydration misapprehensively Bushrope
FileDescription: Prehydration misapprehensively Bushrope
LegalCopyright: Prehydration misapprehensively Bushrope
LegalTrademarks: Prehydration misapprehensively Bushrope
ProductName: Prehydration misapprehensively Bushrope
FileVersion: 7.92
ProductVersion: 7.92
InternalName: cactoid
OriginalFilename: cactoid.exe

Win32/Pronny.CG also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.VB.Agent.3
FireEyeGeneric.mg.4f9405c2ed4e0b90
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.ek
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITWorm.Win32.X-Autorun.BKSE
CyrenW32/VB.HC.gen!Eldorado
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.CG
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.fcga
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Autoruner1.cmxqir
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VBCrypt-BJA [Trj]
RisingWorm.Vobfus!1.99D6 (CLASSIC)
EmsisoftGen:Heur.VB.Agent.3 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.24808
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VB.Agent.3
JiangminTrojan/Vbobf.b
WebrootW32.Worm.Gs
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.CG@4q65me
ArcabitTrojan.VB.Agent.3
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcga
MicrosoftWorm:Win32/Vobfus.GS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R32692
BitDefenderThetaGen:NN.ZevbaF.36250.im0@aKkbz6li
ALYacGen:Heur.VB.Agent.3
TACHYONTrojan/W32.VB-Jorik.135168
VBA32Trojan.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
TencentTrojan.Win32.Vobfus.hbs
YandexTrojan.GenAsa!y9Ragz8q/QE
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BJA [Trj]
Cybereasonmalicious.2ed4e0
DeepInstinctMALICIOUS

How to remove Win32/Pronny.CG?

Win32/Pronny.CG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment