Malware

Win32/Pronny.FQ information

Malware Removal

The Win32/Pronny.FQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Pronny.FQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Pronny.FQ?


File Info:

name: 94DEEA94F9777C9D5252.mlw
path: /opt/CAPEv2/storage/binaries/db654f01e00a0e932d50254732d0a81eb08d42230a2cc03910dd0f474c88f8ec
crc32: 30605860
md5: 94deea94f9777c9d52528ee782e02263
sha1: be449dbf7bdfb2480b9b4a846b3f218b3d745fa6
sha256: db654f01e00a0e932d50254732d0a81eb08d42230a2cc03910dd0f474c88f8ec
sha512: d64abd5ca1c3bcfdcf5bd9b237397494378af6322915b5a609f2ebbcb374a10192cd34b63c2fdc8f339ba912ce5d6ae3a0423f33464617b19e43fc9d91701505
ssdeep: 1536:1iXuJvzDBeZjhtFgGjtXDTto2D9uCLBCPr8/NL44PerViI8kIi/p0:8eJvheZj/FgoTq2lr20
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0C3D53FBA529465E519293029F7C7F616BB6C1A2E0B505B6B0037BB4DB3F000C9DA67
sha3_384: ecd94d9999c280a50aed30a4e316bebe9cf10e5ed033d702843037c8ce8528be8fe05165dddcf765423539ba23549a20
ep_bytes: 689c134000e8eeffffff000000000000
timestamp: 2012-09-25 06:25:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: Coltivare
FileVersion: 5.03
ProductVersion: 5.03
InternalName: Jdavie
OriginalFilename: Jdavie.exe

Win32/Pronny.FQ also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Barys.950
ClamAVWin.Trojan.VB-1720
FireEyeGeneric.mg.94deea94f9777c9d
CAT-QuickHealWorm.VobfusMF.S28101913
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Pronny.ew
VirITTrojan.Win32.Generic.GIZ
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.FQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.abuh
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.bqoefe
AvastWin32:VB-AEOA [Trj]
TencentWorm.Win32.Vobfus.ky
TACHYONWorm/W32.Vobfus.118784
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.26616
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM00
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
IkarusWorm.Win32.Vobfus
GDataWin32.Trojan.PSE.56P7T0
JiangminTrojan/Vbobf.b
WebrootW32.Vobfus
GoogleDetected
AviraTR/Downloader.Gen8
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.Vobfus.118784
ZoneAlarmWorm.Win32.Vobfus.abuh
MicrosoftWorm:Win32/Vobfus.IK
VaristW32/VB.HD.gen!Eldorado
AhnLab-V3Worm/Win32.Vobfus.R37786
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36744.hm0@aasKaKhi
ALYacGen:Variant.Barys.950
MAXmalware (ai score=83)
VBA32Worm.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingWorm.VobfusEx!1.99EB (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4575307.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEOA [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Pronny.FQ?

Win32/Pronny.FQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment