Trojan

Win32/TrojanProxy.JpiProx.B removal

Malware Removal

The Win32/TrojanProxy.JpiProx.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanProxy.JpiProx.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/TrojanProxy.JpiProx.B?


File Info:

name: 87B7F8C291442F5F11B1.mlw
path: /opt/CAPEv2/storage/binaries/64264c4b295533c9a7bab81b135c499da538ea6e71687d1d2012987fd1c5bfbd
crc32: F93CEBD3
md5: 87b7f8c291442f5f11b14635241a6776
sha1: 06c947de9d0db8cd29f9478c2ab32358f0ade7fc
sha256: 64264c4b295533c9a7bab81b135c499da538ea6e71687d1d2012987fd1c5bfbd
sha512: 4600262149754e81c0a16bd8c195ffeaa02ca4b276e480774057a82a0cff39480b14624d107498e3f6e2fd9fa570b0dcb536deecdc783178d6dcca95359e4e64
ssdeep: 12288:h1OgLdaO9uunhwyAcnpDcorrLWweor+SVhZJy5rzELMMzUDX3WsN1eotj:h1OYdaOouRx+oz5HVhuzAVoLHXtj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A15012279E1C472D65310318A98AFE1F5F9F6240B31458BBBD90E2D7F39AA1D327742
sha3_384: 992a80997c2414969fb136bb313b0877cddd74ad94de17f1ad62adc501d08c069e193f935db17c8790d38748c9d9c577
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Win32/TrojanProxy.JpiProx.B also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanDropped:Trojan.GenericKD.1747035
ClamAVWin.Trojan.Bicololo-11
FireEyeDropped:Trojan.GenericKD.1747035
CAT-QuickHealTrojanDropper.Haed.A5
SkyhighBehavesLike.Win32.PUPXGI.cc
McAfeeArtemis!87B7F8C29144
VIPREDropped:Trojan.GenericKD.1747035
SangforSuspicious.Win32.Save.ins
K7AntiVirusProxy-Program ( 004efb261 )
AlibabaTrojan:Win32/JpiProx.725ddc9b
K7GWProxy-Program ( 004efb261 )
ArcabitTrojan.Generic.D1AA85B
BitDefenderThetaGen:NN.ZexaF.36680.tuW@a84KZlpi
VirITTrojan.Win32.MulDrop5.TFB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanProxy.JpiProx.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Wepa.b
BitDefenderDropped:Trojan.GenericKD.1747035
NANO-AntivirusTrojan.Win32.Wepa.dbicod
AvastWin32:Malware-gen
EmsisoftDropped:Trojan.GenericKD.1747035 (B)
F-SecureTrojan.TR/Rogue.327168.3
DrWebTrojan.Siggen6.19313
SophosGeneric Reputation PUA (PUA)
VaristW32/Trojan.AMNU-6634
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.Wepa
KingsoftWin32.Trojan.Wepa.a
XcitiumTrojWare.Win32.Wepa.CDE@5hxtmg
MicrosoftTrojan:Win32/Emotet!ml
ZoneAlarmTrojan.Win32.Wepa.b
GDataDropped:Trojan.GenericKD.1747035
GoogleDetected
ALYacDropped:Trojan.GenericKD.1747035
VBA32Adware.MultiPlug
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingTrojan.Proxy-JpiProx!8.32BC (TFE:5:lZ5MKAlHaPJ)
YandexPUA.Agent!oLP4FA1o/W4
IkarusPUA.Monetizer.Gen7
MaxSecureAdware.JS.MultiPlug.P
FortinetW32/Wepa.B!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/TrojanProxy.JpiProx.B?

Win32/TrojanProxy.JpiProx.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment