Trojan

Trojan.GenericPMF.S18572380 information

Malware Removal

The Trojan.GenericPMF.S18572380 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S18572380 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup

How to determine Trojan.GenericPMF.S18572380?


File Info:

name: 42FFCDBA6064F32768FB.mlw
path: /opt/CAPEv2/storage/binaries/bc183e9dbb4698198ecb26340b7b597111fba6c8d3bb0b2c9939a825dd51ec81
crc32: 559696D6
md5: 42ffcdba6064f32768fb1b3be6a6bf06
sha1: 13ecff98037fd852b7af735773287a997690370c
sha256: bc183e9dbb4698198ecb26340b7b597111fba6c8d3bb0b2c9939a825dd51ec81
sha512: 9de35ab4dfb5b9c731599dee80930b30077f3cbfdda2b220fa2755175755428d808b6470e508f08bf4a586bbd99503a216dcc4da9a85f4b73a330574ab29834a
ssdeep: 768:1DYSAxRjgq8s8nad05psJYXlrbgmIagBr/ugizTzDHzBCGa+S/LIfU/0rhSBXO8:1D/AD8a25aJCrBIagUDBCGa+Sp0rhSBx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AE13E157E7742C4BE5E258B4108F46241712B41EAEA36B6BD512B3CD3DB8176CEC0E4B
sha3_384: 17c9822d298eca4be66ef882f330c597571878000e31a18e8af1f922b7cc43dd67ef6e196c3ca0c03c1a35d93a0daf84
ep_bytes: 60be00f040008dbe0020ffff57eb0b90
timestamp: 2014-12-23 22:22:50

Version Info:

CompanyName: Sun Microsystems, Inc.
FileDescription: Java(TM) Platform SE binary
FileVersion: 6.0.310.5
Full Version: 1.6.0_31-b05
InternalName: java
LegalCopyright: Copyright © 2012
OriginalFilename: java.exe
ProductName: Java(TM) Platform SE 6 U31
ProductVersion: 6.0.310.5
Translation: 0x0000 0x04b0

Trojan.GenericPMF.S18572380 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Tinba.315
MicroWorld-eScanTrojan.Downloader.JTLP
FireEyeGeneric.mg.42ffcdba6064f327
CAT-QuickHealTrojan.GenericPMF.S18572380
McAfeeGenericRXAA-AA!42FFCDBA6064
CylanceUnsafe
ZillyaDownloader.JTLP.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005716121 )
K7GWTrojan ( 005716121 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.34062.cmLfaSLNb@p
CyrenW32/Tinba.O.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.CYQI
ClamAVWin.Trojan.Tinba-6390856-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JTLP
NANO-AntivirusTrojan.Win32.Hupigon.dszayy
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b48cc5
Ad-AwareTrojan.Downloader.JTLP
EmsisoftTrojan.Downloader.JTLP (B)
ComodoTrojWare.Win32.Hupigon.A@6l61p1
BaiduWin32.Trojan.Kryptik.aww
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
SophosML/PE-A + Troj/Tinba-EU
IkarusTrojan.Crypt
GDataWin32.Trojan.PSE.1B1JBEL
JiangminTrojan.Generic.ekaor
AviraHEUR/AGEN.1120545
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.F4CDA8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.R281538
Acronissuspicious
VBA32TrojanPSW.Tinba
ALYacTrojan.Downloader.JTLP
TACHYONTrojan/W32.Agent.90368.X
MalwarebytesBackdoor.Agent.JV
APEXMalicious
RisingTrojan.Kryptik!1.A6CB (CLASSIC)
YandexTrojan.GenAsa!O5DYBSlOBw8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Tinba.BF!tr
AVGWin32:Malware-gen
Cybereasonmalicious.a6064f
PandaTrj/Genetic.gen

How to remove Trojan.GenericPMF.S18572380?

Trojan.GenericPMF.S18572380 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment