Worm

Worm:Win32/Prolaco.T removal instruction

Malware Removal

The Worm:Win32/Prolaco.T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Prolaco.T virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings

Related domains:

www.whatismyip.com

How to determine Worm:Win32/Prolaco.T?


File Info:

crc32: FFCCD08A
md5: 4f943557e9b7717b2b0ccc8e409fdbfe
name: 4F943557E9B7717B2B0CCC8E409FDBFE.mlw
sha1: c97be69e99df732da14d5bddaffa37f51fb5ec08
sha256: 3f48e84f60630ff5a6cda07423e42317ba9d6d15a8e8478654c8d5da7ac5b89e
sha512: 4e302900862f653941ff9abf8ce6e7de164787841d32768fb509f75a83b795d77f691cd87849073f50a28d375e36f581e8623946123da5a5895ab4e17756915b
ssdeep: 12288:MJP4Yl5DY3QDUczlESyslf3JFuin9V3Fp1wOyt5ydSR1:M2qEADnzlESLbV9tD1Fytw01
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.2900.5512
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Worm:Win32/Prolaco.T also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop1.34269
ClamAVWin.Trojan.Agent-228853
ALYacGen:Heur.Mint.Zard.10
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 0055e3991 )
K7AntiVirusTrojan ( 0055e3991 )
CyrenW32/Risk.WHJT-1280
SymantecW32.Ackantta@mm
ESET-NOD32a variant of Win32/Merond.AC
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.fqgd
BitDefenderGen:Heur.Mint.Zard.10
NANO-AntivirusTrojan.Win32.Typic.deauuf
MicroWorld-eScanGen:Heur.Mint.Zard.10
Ad-AwareGen:Heur.Mint.Zard.10
SophosMal/Generic-R
ComodoSuspicious@#2w4xhzkuelv86
BitDefenderThetaAI:Packer.7F61AD191F
VIPREWorm.Win32.Prolaco (v)
TrendMicroWORM_PROLACO.SMA
McAfee-GW-EditionGenericRXOX-AV!D52678C5E48D
FireEyeGen:Heur.Mint.Zard.10
EmsisoftGen:Heur.Mint.Zard.10 (B)
JiangminTrojanDropper.Typic.ox
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7B6D40
MicrosoftWorm:Win32/Prolaco.T
ZoneAlarmTrojan-Ransom.Win32.Blocker.fqgd
GDataWin32.Trojan.Prolaco.A
McAfeeArtemis!4F943557E9B7
MAXmalware (ai score=84)
VBA32TrojanDropper.Typic
MalwarebytesTrojan.Extension.Exploit
TrendMicro-HouseCallWORM_PROLACO.SMA
YandexTrojan.GenAsa!ZaG98QaFTR0
MaxSecureVirus.W32.Cabres.a
FortinetW32/Agent.0FA5!tr.dldr
AVGWin32:Malware-gen

How to remove Worm:Win32/Prolaco.T?

Worm:Win32/Prolaco.T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment