Trojan

Trojan.PRForm.B removal instruction

Malware Removal

The Trojan.PRForm.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.PRForm.B virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.PRForm.B?


File Info:

name: 5A4091C6BBC1094E442C.mlw
path: /opt/CAPEv2/storage/binaries/c53f889286aa97702ba3a692e1acafdf0c170b466900c42e7b20bf69447754f9
crc32: 8C5EAFFA
md5: 5a4091c6bbc1094e442c3d6d27722945
sha1: d5cafdd41bec6f4fd2a0e945c65b4c978510ff11
sha256: c53f889286aa97702ba3a692e1acafdf0c170b466900c42e7b20bf69447754f9
sha512: 7bbc7e102680681cc39c47e0190e582da0ada9611e27fe54dfc5ad0b808cc45755401da45ee4ac122b887f868b0e663237f5fcb3037cbcbf669386855f00b5b7
ssdeep: 98304:LZSlUtgzUQ+/XPSstR3iRzZkVrqOAgjCdiPujJFPGctXLcaZ5G:FtgaSGR3cd9gG8Gtx9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8A68E21B791C066E5A71270D87AD6F127A6FD30C930878B769C3E6F3F306D14A2C696
sha3_384: 7529bf7ce167f75536a2dee680693472f9b77c141d6c27466f3cb4ee76e7989b9de4a9dd9b0c0ae3905c89c66f036412
ep_bytes: e83c0b0000e98efeffff6860087a01ff
timestamp: 2017-08-03 09:37:49

Version Info:

Comments: CCleaner
CompanyName: Piriform Ltd
FileDescription: CCleaner
FileVersion: 5, 33, 00, 6162
InternalName: ccleaner
LegalCopyright: Copyright © 2005-2017 Piriform Ltd
OriginalFilename: ccleaner.exe
ProductName: CCleaner
ProductVersion: 5, 33, 00, 6162
Translation: 0x0409 0x04b0

Trojan.PRForm.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.InfeCleaner.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeTrojan.PRForm.B
McAfeeArtemis!5A4091C6BBC1
VIPRETrojan.PRForm.B
SangforBackdoor.Win32.Infecleaner.Vm0v
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderTrojan.PRForm.B
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.6bbc10
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DHKXUQP
ClamAVWin.Spyware.CCBkdr-6336251-2
KasperskyBackdoor.Win32.InfeCleaner.a
AlibabaBackdoor:Win32/InfeCleaner.2f803a65
NANO-AntivirusTrojan.Win32.InfeCleaner.jyxsrx
MicroWorld-eScanTrojan.PRForm.B
AvastWin32:TlsHack-A [Trj]
TencentWin32.Backdoor.Infecleaner.Zylw
SophosTroj/Mogoa-A
F-SecureBackdoor.BDS/InfoCleaner.vgsst
TrendMicroBKDR_CCHACK.SM
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
EmsisoftTrojan.PRForm.B (B)
GDataTrojan.PRForm.B
AviraBDS/InfoCleaner.vgsst
Antiy-AVLTrojan[Backdoor]/Win32.InfeCleaner
ArcabitTrojan.PRForm.B
ZoneAlarmBackdoor.Win32.InfeCleaner.a
GoogleDetected
AhnLab-V3Backdoor/Win.InfeCleaner.C5469114
ALYacTrojan.PRForm.B
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_CCHACK.SM
RisingBackdoor.ModifiedCCleaner!1.A3B5 (CLASSIC)
IkarusPUA.Crack
FortinetW32/HackedCCleaner.A!tr
AVGWin32:TlsHack-A [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.PRForm.B?

Trojan.PRForm.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment