Malware

About “Dropped:Application.crack.PFL” infection

Malware Removal

The Dropped:Application.crack.PFL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Application.crack.PFL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key

Related domains:

bit.do
rebrand.ly
jamshed.pk
backgrounds.pk
karimgousa.ug
karimgouss.ug

How to determine Dropped:Application.crack.PFL?


File Info:

crc32: 1DE25DD6
md5: 1fb060d7141deadc6675723d6dd905fc
name: 1FB060D7141DEADC6675723D6DD905FC.mlw
sha1: 56e830b1cd6126e1495fdfffef3fd907d2eeb89e
sha256: bd95c8709b9a82ab2af9d1454996fbdbd3a7da4e8335bf8481bd567430130184
sha512: d4de33220b26fb64d7721630e3a365fc0e0dd9c9aa0d652dd9cc8aeddc53d0d320c10bae93d71db2ccf46af725faf5abdcd32a509584d658c0dc556097edd596
ssdeep: 12288:tivlI1n+cWJZap6uwTr9io6dB+9mH6T8OwaTNxp55ZJ0tfuFtGtLOtHoS:tQ2+Sp2TrcoCB+9xhzhxp55ZJArt
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Dropped:Application.crack.PFL also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanDropped:Application.crack.PFL
FireEyeGeneric.mg.1fb060d7141deadc
CAT-QuickHealTrojanpws.Azorult
Qihoo-360Win32/Trojan.PSW.b8b
McAfeeArtemis!1FB060D7141D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005692391 )
BitDefenderDropped:Application.crack.PFL
K7GWTrojan ( 005692391 )
Cybereasonmalicious.7141de
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34136.PmGfaaqCtiBi
CyrenW32/Application.VWZD-3773
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EMKM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Crack-6988654-0
KasperskyTrojan-PSW.Win32.Racealer.gnl
AlibabaTrojanPSW:Win32/Racealer.8e4814bb
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10cdd703
EmsisoftDropped:Application.crack.PFL (B)
ComodoMalware@#bttezrrqw9ro
F-SecureTrojan.TR/Injector.tuhta
DrWebTrojan.DownLoader33.53544
TrendMicroTROJ_GEN.R002C0PFJ20
FortinetW32/GenKryptik.ELSW!tr
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
JiangminTrojan.Multi.dd
AviraTR/Injector.tuhta
MAXmalware (ai score=71)
Antiy-AVLTrojan/BAT.KillWin
ArcabitApplication.crack.PFL
ZoneAlarmTrojan-PSW.Win32.Racealer.gnl
MicrosoftTrojan:Win32/Ymacco.AA70
CynetMalicious (score: 85)
VBA32TrojanBanker.Qhost
Ad-AwareDropped:Application.crack.PFL
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002H0CFJ20
RisingTrojan.Injector!1.C6AF (CLOUD)
YandexTrojan.Injector!bDOz86KbktE
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_100%
GDataDropped:Application.crack.PFL
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Dropped:Application.crack.PFL?

Dropped:Application.crack.PFL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment