Backdoor

Backdoor:Win32/Prisos.A removal instruction

Malware Removal

The Backdoor:Win32/Prisos.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Prisos.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

How to determine Backdoor:Win32/Prisos.A?


File Info:

name: CF2924E55511FCFA52B5.mlw
path: /opt/CAPEv2/storage/binaries/855047b19679427acd5d11bfbda6ef538e3a79c23b83d3ee182177865872b812
crc32: A9FB6A68
md5: cf2924e55511fcfa52b5f11595537b20
sha1: 20d5d70ff358746d4f0e8932869e511af35cd488
sha256: 855047b19679427acd5d11bfbda6ef538e3a79c23b83d3ee182177865872b812
sha512: 08e56d2370f10bc933715ee0230b706f5fb99e9516bb1a7696e87de5a04efd45e490de792dae22e1a7bbf476bac4fc0b278c341e12358cac4a2b09699b1715a7
ssdeep: 1536:6mVZQJxFnGqow0B2Kvfqf/rpRq+cx6xKvqEam:6mgxGqow0B2KvMJxKvqO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A532A37B8D58C62F586A57504364B7A6E3BF8711694838B9F106E6D2C32390EE3934B
sha3_384: 5e28b1d32cefe4dbe56566aca12493d1b45e7afbe339d1c086ebe5865b00eeb1b2121c0afca852f96478d1a64f4a6d32
ep_bytes: 558bec6aff684071400068144f400064
timestamp: 2007-12-06 05:24:26

Version Info:

0: [No Data]

Backdoor:Win32/Prisos.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.11608
FireEyeGeneric.mg.cf2924e55511fcfa
McAfeeBackDoor-YA.a
CylanceUnsafe
VIPREBackdoor.Win32.Prisos.A (v)
K7AntiVirusTrojan ( 004d07a21 )
K7GWTrojan ( 004d07a21 )
Cybereasonmalicious.55511f
BaiduWin32.Backdoor.Prisos.b
VirITTrojan.Win32.TianYan.B
CyrenW32/Trojan.HMGX-6351
SymantecW32.Killaut.A
ESET-NOD32Win32/Prisos.A
APEXMalicious
ClamAVWin.Spyware.35814-2
KasperskyTrojan.Win32.Agent.netfau
BitDefenderGen:Variant.Doina.11608
NANO-AntivirusTrojan.Win32.TianYan.cqjjhu
AvastWin32:Dropper-FJM [Drp]
TencentMalware.Win32.Gencirc.10b18485
Ad-AwareGen:Variant.Doina.11608
SophosTroj/Agent-ICR
ComodoTrojWare.Win32.TrojanSpy.TianYan.~A@1qz4h
DrWebWin32.HLLP.Nemesis.28687
TrendMicroTSPY_TIANYAN.SMD
McAfee-GW-EditionBackDoor-YA.a
EmsisoftGen:Variant.Doina.11608 (B)
GDataGen:Variant.Doina.11608
JiangminTrojanSpy.TianYan.a
eGambitUnsafe.AI_Score_66%
AviraTR/Spy.Genome.rlce
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.AE45
KingsoftHeur.SSC.2622419.1216.(kcloud)
ViRobotTrojan.Win32.TianYan.40960
MicrosoftBackdoor:Win32/Prisos.A
CynetMalicious (score: 99)
AhnLab-V3Worm/Win32.Mabezat.R26794
BitDefenderThetaGen:NN.ZexaCO.34114.dqY@aOJOHJcO
ALYacGen:Variant.Doina.11608
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesMalware.AI.825262803
TrendMicro-HouseCallTSPY_TIANYAN.SMD
RisingTrojan.Spy.Win32.TianYan.a (RDMK:cmRtazqfQge9rhDQzrzwofJL50yf)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.1F6EC8!tr
AVGWin32:Dropper-FJM [Drp]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor:Win32/Prisos.A?

Backdoor:Win32/Prisos.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment