Malware

Win32/ProxyChanger.WS (file analysis)

Malware Removal

The Win32/ProxyChanger.WS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ProxyChanger.WS virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Sets an Autoconfig URL, likely to hijack browser settings.
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

www.baidu.com
dns.ke99l.cn
pac.ke99l.cn
redirector.gvt1.com

How to determine Win32/ProxyChanger.WS?


File Info:

crc32: A010F5C0
md5: 4db4b3223f415040578fd8e778b8dfc3
name: www1.jpg
sha1: 2c32846118a3618f26caff6beea0a2692049353c
sha256: 77d90f5f6f88e71d6518da7acbbb2a7c21b972a2776d37d1cff8edf6dfdb2e47
sha512: ba5f964f406904195e3794711f41bc8564e5e32a87cf1e057c342f883aa9f6d64a585bee2b7a312ca0d777cfad630648d79bd51c43561c85a5eb0126b27f5e74
ssdeep: 3072:c4NRCfjKUWsP+umgiRwAdbVDsGbh5qcFCR9f7LIKPJ66wQlXS/VJAzQoAYbHpG:BLCfjKImdrdZoW+cu+KRQQlYjep
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/ProxyChanger.WS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.264388
FireEyeGen:Variant.Johnnie.264388
CAT-QuickHealTrojan.Banbra
Qihoo-360Generic/Trojan.e3e
McAfeeArtemis!4DB4B3223F41
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Banbra.7!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Johnnie.264388
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R011C0WHN20
CyrenW32/Trojan.LEGD-6361
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Banbra.wuit
AlibabaTrojanBanker:Win32/Banbra.20e172c7
NANO-AntivirusTrojan.Win32.Banbra.hsyaph
ViRobotTrojan.Win32.Z.Banbra.298496
Ad-AwareGen:Variant.Johnnie.264388
F-SecureTrojan.TR/Spy.Banbra.juklk
DrWebTrojan.DnsChange.16523
ZillyaTrojan.ProxyChanger.Win32.2101
InvinceaMal/Generic-S
SophosMal/Generic-S
IkarusTrojan.Spy.Banbra
JiangminTrojan.Banker.Banbra.esy
AviraTR/Spy.Banbra.juklk
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Ymacco.AA77
ArcabitTrojan.Johnnie.D408C4
ZoneAlarmTrojan-Banker.Win32.Banbra.wuit
GDataGen:Variant.Johnnie.264388
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZexaE.34216.suW@aS0NHqni
ALYacGen:Variant.Johnnie.264388
VBA32TrojanBanker.Banbra
ESET-NOD32a variant of Win32/ProxyChanger.WS
TrendMicro-HouseCallTROJ_GEN.R011C0WHN20
TencentWin32.Trojan-banker.Banbra.Pgwy
eGambitUnsafe.AI_Score_91%
FortinetW32/Banbra.WUIT!tr
AVGWin32:Malware-gen
Cybereasonmalicious.118a36
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.1728101.susgen

How to remove Win32/ProxyChanger.WS?

Win32/ProxyChanger.WS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment