Malware

What is “Win32/Pronny.FR”?

Malware Removal

The Win32/Pronny.FR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Pronny.FR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/Pronny.FR?


File Info:

name: 5E613C5AACAA72E55A7C.mlw
path: /opt/CAPEv2/storage/binaries/d4db2abbd6ff15097a0d5c612a099e1ab1357cde9578095d9b209668fda4e702
crc32: 2CF2BFFD
md5: 5e613c5aacaa72e55a7c47b7f4d98a11
sha1: 65fbf86a780a9968246ad093480e9d554f4eb018
sha256: d4db2abbd6ff15097a0d5c612a099e1ab1357cde9578095d9b209668fda4e702
sha512: 4bdd6c2abc859018dd83a8fc032f7d93b241777731533a26897e888b6302a702cca16ef2bce292947a338dbdffd909a41e87f6644389948b77c7f37d72683670
ssdeep: 768:cdSbVkZtBTSD9mx0CjIGhY4VVN2b1LllfRddcQVEWeSgPl53XXT+AeZO:cdwV2q9Cr0GhXKdTdTiWeDPv3XAZO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11093A43FBF86405AE548563026F6C7E61ABB581B5B2B100BE704F7552DE7E240C2CEA7
sha3_384: 3e12a288e5c9a3e53607d85d790bd00435bcebcf8c3a1defd63fd6fc7b59c7570ed125283483167f0d4e590fc161b33d
ep_bytes: 68bc124000e8eeffffff000000000000
timestamp: 2012-10-08 17:42:11

Version Info:

Translation: 0x0409 0x04b0
ProductName: lapithae
FileVersion: 0.40
ProductVersion: 0.40
InternalName: Confed
OriginalFilename: Confed.exe

Win32/Pronny.FR also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.2430
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.nm
ALYacGen:Variant.Symmi.2430
MalwarebytesPronny.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
ArcabitTrojan.Symmi.D97E
VirITWorm.Win32.VB.KK
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.FR
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMQ5
ClamAVWin.Trojan.VB-1717
KasperskyWorm.Win32.Vobfus.wdd
BitDefenderGen:Variant.Symmi.2430
NANO-AntivirusTrojan.Win32.Vobfus.cmxpyc
AvastWin32:Sality-KYG
TencentMalware.Win32.Gencirc.10b1515d
TACHYONWorm/W32.Vobfus.94208
EmsisoftGen:Variant.Symmi.2430 (B)
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.27439
VIPREGen:Variant.Symmi.2430
TrendMicroWORM_VOBFUS.SMQ5
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.5e613c5aacaa72e5
SophosMal/SillyFDC-Y
IkarusWorm.Win32.VBNA
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Downloader.Gen8
VaristW32/VB.HE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Pronny.EB@4qtzpj
MicrosoftWorm:Win32/Vobfus!pz
ZoneAlarmWorm.Win32.Vobfus.wdd
GDataGen:Variant.Symmi.2430
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R39146
McAfeeGenDownloader.rv
MAXmalware (ai score=80)
VBA32Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Vobfus!8.10E (TFE:3:L0fVyQLT3SL)
YandexTrojan.GenAsa!HzAOoEFks5w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4658071.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaGen:NN.ZevbaF.36804.fm0@am6iPili
AVGWin32:Sality-KYG
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.1211a966

How to remove Win32/Pronny.FR?

Win32/Pronny.FR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment