Malware

What is “Generic.Malware.PfBPk!1g.5A0FDA9D”?

Malware Removal

The Generic.Malware.PfBPk!1g.5A0FDA9D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Malware.PfBPk!1g.5A0FDA9D virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generic.Malware.PfBPk!1g.5A0FDA9D?


File Info:

name: 02D7D25C2F0D38040D6C.mlw
path: /opt/CAPEv2/storage/binaries/435fbd423f30e3508f428d828b7d06f4e4e553303da0aee6e1126d06cc1ef55c
crc32: AE06ABBF
md5: 02d7d25c2f0d38040d6c95ef459a993c
sha1: 2f9cc29301a7cafa1d566301c2ef2ad167411565
sha256: 435fbd423f30e3508f428d828b7d06f4e4e553303da0aee6e1126d06cc1ef55c
sha512: ee75959028b9f25be14ff8d48f1a9884b4bec88d2f5dec3e113f89f58950e333148e94b493114f6b65012aefda92cf54cd7f8ee1ed9775be451b172c0f5c5a69
ssdeep: 3072:cPtLt9VcVxBiB2yK1w/F01hpYI3hfqnBv/hjJANwdi+O1BGf:cPtLt9VSBrZw/UbhCBBqwdRW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED04CF1231D488B2E563067089A9EB621A7DFC705975589FABE42E7F2F746C2C23D343
sha3_384: 12cdf314d917c9bae045ef90ce8828a4747e9d7a3384f81dde17844d922cd35c3daf15114a8a3a145d1c83bee9583bda
timestamp: 2014-09-26 08:16:55

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Services
FileVersion: 6.1.7600.16385
InternalName: svchost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: svchost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Generic.Malware.PfBPk!1g.5A0FDA9D also known as:

LionicTrojan.Win32.PfBPk.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.PfBPk!1g.5A0FDA9D
FireEyeGeneric.mg.02d7d25c2f0d3804
CylanceUnsafe
VIPREGeneric.Malware.PfBPk!1g.5A0FDA9D
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Generic.17db566d
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.EWI.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Agent.RLQ
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGeneric.Malware.PfBPk!1g.5A0FDA9D
Ad-AwareGeneric.Malware.PfBPk!1g.5A0FDA9D
EmsisoftGeneric.Malware.PfBPk!1g.5A0FDA9D (B)
F-SecureTrojan.TR/AD.Miniduke.jlgtm
ZillyaTrojan.Agent.Win32.1494865
McAfee-GW-EditionBehavesLike.Win32.BadFile.ch
Trapminemalicious.high.ml.score
SophosGeneric PUA CP (PUA)
SentinelOneStatic AI – Malicious PE
GDataGeneric.Malware.PfBPk!1g.5A0FDA9D
AviraTR/AD.Miniduke.jlgtm
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacGeneric.Malware.PfBPk!1g.5A0FDA9D
MAXmalware (ai score=81)
ZonerProbably Heur.ExeHeaderL
RisingTrojan.Generic@AI.83 (RDML:hWfv3I6ofxnktL8N6H7nrQ)
IkarusTrojan.Win32.Agent
FortinetW32/Agent.RLQ!tr
Cybereasonmalicious.c2f0d3

How to remove Generic.Malware.PfBPk!1g.5A0FDA9D?

Generic.Malware.PfBPk!1g.5A0FDA9D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment