Trojan

Trojan.AgentPMF.S26014015 malicious file

Malware Removal

The Trojan.AgentPMF.S26014015 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentPMF.S26014015 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Trojan.AgentPMF.S26014015?


File Info:

name: 305E96F02AD52489D580.mlw
path: /opt/CAPEv2/storage/binaries/42aeb50e9bda226e893372f32deb8d295ef6efb896b96c7b8eb0c15539edddaa
crc32: 35841E40
md5: 305e96f02ad52489d58025948f433f00
sha1: 468de6c72f30ffd6af082dee03462d0a1d46540f
sha256: 42aeb50e9bda226e893372f32deb8d295ef6efb896b96c7b8eb0c15539edddaa
sha512: 9d5e1c1ec3519b98a3d2a66f796ada6dfce3b941fb6f7a6345b6ec794938e27eee1e5d67c2164eb8422cd3407327add96155ee3a131202d3a1b33bbe832b74b8
ssdeep: 1536:eFGZQkskqDXPwxO+ct8q0QO2zzNrKly+jbMAemotchI2WkLnYKMhs0g:pRz0Wct8WOoNrr+jQAHotchikLnMhs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19534AE1276E0F832F5A215344874D6976E3BF9526A24D08F77583BAE6F322805F36372
sha3_384: 35d4adc6b578d47c539db0c8bad0497e7b33250e9480736f34a14e662dbf5611da4e5c8ed91d48767fd2125dd9eb98f8
ep_bytes: e8e0330000e978feffffcccccccccccc
timestamp: 2021-07-09 06:38:16

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.70.77
Translation: 0x0129 0x0794

Trojan.AgentPMF.S26014015 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47830185
FireEyeGeneric.mg.305e96f02ad52489
CAT-QuickHealTrojan.AgentPMF.S26014015
McAfeePacked-GEE!305E96F02AD5
CylanceUnsafe
ZillyaTrojan.Smokeloader.Win32.649
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577cca1 )
AlibabaRansom:Win32/StopCrypt.40a424c4
K7GWTrojan ( 00577cca1 )
Cybereasonmalicious.72f30f
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Smokeloader.F
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.47830185
AvastWin32:AceCrypter-B [Cryp]
TencentWin32.Trojan.Agent.Lgtq
Ad-AwareTrojan.GenericKD.47830185
SophosMal/Generic-S + Mal/Agent-AWV
ComodoMalware@#3tzks2fw8fsu7
DrWebTrojan.Siggen16.26270
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.BSE.16VOW5Z
JiangminTrojan.Agent.dtxp
eGambitUnsafe.AI_Score_79%
AviraTR/Crypt.XPACK.sbees
GridinsoftRansom.Win32.STOP.sa
ViRobotTrojan.Win32.S.Dropper.252416
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftRansom:Win32/StopCrypt.MZE!MTB
TACHYONTrojan/W32.Agent.252416.IR
AhnLab-V3Trojan/Win.MalPE.R462691
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34182.puW@aenoVEjK
ALYacTrojan.GenericKD.47830185
MAXmalware (ai score=88)
VBA32BScope.TrojanSpy.Convagent
MalwarebytesTrojan.MalPack
RisingTrojan.Agent!8.B1E (CLOUD)
YandexTrojan.Smokeloader!ay2jDceEs8k
IkarusTrojan.Win32.Raccrypt
FortinetW32/Kryptik.HOCG!tr
WebrootW32.Trojan.Gen
AVGWin32:AceCrypter-B [Cryp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AgentPMF.S26014015?

Trojan.AgentPMF.S26014015 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment