Trojan

Trojan.GenericPMF.S1550930 removal

Malware Removal

The Trojan.GenericPMF.S1550930 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S1550930 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • A script process created a new process

How to determine Trojan.GenericPMF.S1550930?


File Info:

name: EE02DDE4DF0AAB8DAC1D.mlw
path: /opt/CAPEv2/storage/binaries/cf4270c269e3e50d162859582c65cbce5f378b1f238980336a5dbe11decc4104
crc32: BFE576AE
md5: ee02dde4df0aab8dac1dfc5417160281
sha1: 7ad9c88ceef6252e9d0d4dccff31af1d3d2ef679
sha256: cf4270c269e3e50d162859582c65cbce5f378b1f238980336a5dbe11decc4104
sha512: 6ab0ba301a5960594fa0bfed64aac263052c3d4a37de35c68b581702581d408ab7f441f460ccd6da81f5e803a023fb5e85cc801ffcf3ec26dae280dcd37caab5
ssdeep: 768:TLdXgcwcQs8vllhkEUOd5H/KeGJjpUZca/nbcuyD7U/EO:TLOmJ8vllh6OdoeuUqa/nouy88O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8F2E166E56E8D90C4594AB11CCD786A4584D3172987A3C2B34D22FDFF90EB41F1A732
sha3_384: ce978137f3203e4454d39165789b1c13b39c081bb8b625ebed7c82583d927dea966a0dafb6c671bf5e1efebbe6c38b89
ep_bytes: 60be15f040008dbeeb1fffff5789e58d
timestamp: 2016-05-27 14:21:33

Version Info:

0: [No Data]

Trojan.GenericPMF.S1550930 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S1550930
MalwarebytesMalware.AI.356514689
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Agent.BJD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.0040eff-6976969-0
ComodoMalware@#2re2rgk5o4p92
McAfee-GW-EditionBehavesLike.Win32.Pate.nc
FireEyeGeneric.mg.ee02dde4df0aab8d
SophosGeneric ML PUA (PUA)
JiangminRiskTool.BitCoinMiner.pd
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.18EDCBD
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C2957633
Acronissuspicious
McAfeeGenericRXAA-AA!EE02DDE4DF0A
VBA32Trojan.BtcMine
CylanceUnsafe
YandexTrojan.GenAsa!pnOFf4yqwy0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.36BC4F!tr
BitDefenderThetaGen:NN.ZexaF.34062.cmGfaSB5BEl
AVGWin32:Malware-gen
Cybereasonmalicious.ceef62
Paloaltogeneric.ml

How to remove Trojan.GenericPMF.S1550930?

Trojan.GenericPMF.S1550930 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment