Trojan

Trojan.AgentPMF.S24807869 removal guide

Malware Removal

The Trojan.AgentPMF.S24807869 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentPMF.S24807869 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan.AgentPMF.S24807869?


File Info:

name: A141E7C9EC99046D7BA2.mlw
path: /opt/CAPEv2/storage/binaries/556660352fbac7a00fd4409c11d8949a5d9f7e43a516e5fd3cd4c7b49cce9afc
crc32: 76511E88
md5: a141e7c9ec99046d7ba2d515da107409
sha1: 55a37fdddec2f8fb3d47613f61e6681289755781
sha256: 556660352fbac7a00fd4409c11d8949a5d9f7e43a516e5fd3cd4c7b49cce9afc
sha512: 42e714734d6dc83c8f9d7634536d5bd8732b98e0043d7451d9fb57c8978a05488d14518cd0aada346603535be70667abbb1c579d2ed20854ed9a9698dceb2728
ssdeep: 24576:+GUFNvFAgoydO0RDLkYBRaJ6bM7mKLd+1zZb1:sFNvFA9ml/IJ6B1zj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E345AE217541C032E6B300B1997EDB6A453CFD21072694D7E3D8782E9EB09C2BB3A797
sha3_384: f101a15d9483f7b3579144f4deb633a2c476101bfa67e149d93732591d53be2725f20edad8156557d9c6e3d8e17f7c58
ep_bytes: e89f050000e98efeffff558bec6a00ff
timestamp: 2021-04-15 09:24:05

Version Info:

Comments: www.glzip.com
CompanyName: 上海广乐网络科技有限公司
FileDescription: KZReport
FileVersion: 3.3.0.3
InternalName: KZReport
LegalCopyright: 上海广乐网络科技有限公司
OriginalFilename: KZReport.exe
ProductName: 快压
ProductVersion: 3.3.0.3
Translation: 0x0804 0x04b0

Trojan.AgentPMF.S24807869 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.KuziTui.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.lz2@Y6KbGhoj
FireEyeGeneric.mg.a141e7c9ec99046d
CAT-QuickHealTrojan.AgentPMF.S24807869
McAfeePUP-XQT-ZC
CylanceUnsafe
VIPREVirus.Win32.Sality.atbh (v)
SangforVirus_Suspicious.Win32.Sality.bh
K7AntiVirusAdware ( 00565ab71 )
AlibabaAdWare:Win32/KZip.2fd
K7GWAdware ( 00565ab71 )
Cybereasonmalicious.9ec990
CyrenW32/KuaiZip.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KuaiZip.AB potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:AdWare.Win32.KuziTui.gen
BitDefenderGen:Trojan.Heur.lz2@Y6KbGhoj
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Sality [Inf]
TencentPua:Adware.Win32.Kuzitui.16000042
Ad-AwareGen:Trojan.Heur.lz2@Y6KbGhoj
EmsisoftGen:Trojan.Heur.lz2@Y6KbGhoj (B)
ZillyaAdware.KuziTui.Win32.1429
TrendMicroTROJ_GEN.R002C0WKI21
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosGeneric PUA FF (PUA)
IkarusPUA.Adposhel
GDataGen:Trojan.Heur.lz2@Y6KbGhoj
JiangminAdWare.KuziTui.abv
Antiy-AVLTrojan/Generic.ASMalwS.333D4B2
ArcabitTrojan.Heur.E215C1
ViRobotAdware.Kuzitui.1237896.C
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.RL_Generic.R371064
Acronissuspicious
BitDefenderThetaAI:Packer.60FAC2351C
ALYacGen:Trojan.Heur.lz2@Y6KbGhoj
MAXmalware (ai score=89)
VBA32BScope.Adware.Burden
MalwarebytesPUP.Optional.ChinAd
TrendMicro-HouseCallTROJ_GEN.R002C0WKI21
RisingAdware.Agent!1.C6CF (CLASSIC)
YandexPUA.KuziTui!n3flUMMIUr4
SentinelOneStatic AI – Malicious PE
MaxSecureAdware.WIN32.KuziTui.gen_217964
FortinetAdware/KuaiZip.AB
AVGWin32:Sality [Inf]

How to remove Trojan.AgentPMF.S24807869?

Trojan.AgentPMF.S24807869 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment