Worm

About “Worm:Win32/Pricbot.B” infection

Malware Removal

The Worm:Win32/Pricbot.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Pricbot.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings

How to determine Worm:Win32/Pricbot.B?


File Info:

name: 5A7556B1055D2D442B2C.mlw
path: /opt/CAPEv2/storage/binaries/1da804ff4ef277f0a4626a844f6ea4db0e531f44ee4f921dae8d18dba72871b5
crc32: FE0267B3
md5: 5a7556b1055d2d442b2c271317bd3281
sha1: 2220274187dd4fa74e7c4c6511edc924bb2118c9
sha256: 1da804ff4ef277f0a4626a844f6ea4db0e531f44ee4f921dae8d18dba72871b5
sha512: 4d912e52baed4fd86bab14d88c7709f4aa68676eddcf37050bb62f01be51eb52ac624a96659b1b218d89839d7c9293276497b58bdcbfe6fca3317d6ea04b3c40
ssdeep: 12288:n6qtRtAfQLsKyX9KHk27eWhXOIK81wj1:FtRtAfQLn0kDZXO42j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DD41810EB41A069FED701F79EFD59AC9068B9304BCC24C7B1C896AD52AA7E136371C7
sha3_384: da225c975292152953494ed272d01fc7118ac453ddd847834d089afd5afc96b4bb2ece18496dba7b72907df242d2c691
ep_bytes: e9ac210500e977810500e9b2070200e9
timestamp: 2009-12-06 15:49:25

Version Info:

0: [No Data]

Worm:Win32/Pricbot.B also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Raldhep.1
FireEyeGeneric.mg.5a7556b1055d2d44
ALYacGen:Variant.Raldhep.1
CylanceUnsafe
VIPREGen:Variant.Raldhep.1
K7AntiVirusHacktool ( 0052860f1 )
K7GWHacktool ( 0052860f1 )
Cybereasonmalicious.1055d2
VirITBackdoor.Win32.Bot.NG
SymantecW32.Imaut
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.IRCBot.EO
APEXMalicious
ClamAVWin.Trojan.Agent-436398
KasperskyBackdoor.Win32.Brabot.ct
BitDefenderGen:Variant.Raldhep.1
NANO-AntivirusTrojan.Win32.Jorik.bwuxa
AvastFileRepMalware [Misc]
Ad-AwareGen:Variant.Raldhep.1
SophosMal/Generic-R + Mal/IRCBot-N
DrWebBackDoor.IRC.Bot.344
ZillyaWorm.AutoRun.Win32.18425
McAfee-GW-EditionBehavesLike.Win32.Dropper.jm
EmsisoftGen:Variant.Raldhep.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Raldhep.1
JiangminTrojan/Jorik.cll
AviraBDS/Backdoor.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.1EF0
MicrosoftWorm:Win32/Pricbot.B
CynetMalicious (score: 99)
McAfeePWS-Zbot.gen.xa
VBA32Win32.AutoRun.IRCBot
MalwarebytesMalware.AI.1428167357
YandexWorm.AutoRun!hASpyxz7Y8o
IkarusTrojan.Win32.Jorik
FortinetW32/IRCBot.EO!tr.pws
BitDefenderThetaGen:NN.ZexaF.34786.NyW@am7rJYcG
AVGFileRepMalware [Misc]
PandaW32/IRCbot.CSX
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm:Win32/Pricbot.B?

Worm:Win32/Pricbot.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment