Trojan

Trojan.GenericPMF.S2752897 (file analysis)

Malware Removal

The Trojan.GenericPMF.S2752897 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S2752897 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.GenericPMF.S2752897?


File Info:

name: 5E7637BADBEE5478409D.mlw
path: /opt/CAPEv2/storage/binaries/0f806a850507561d4e5efe13ee47b660cdf04465017a7c41fff1ccdb8d497fe6
crc32: 1BBF1038
md5: 5e7637badbee5478409da27113608fd6
sha1: 2049173bf68f52fb2a22cb80f70ffb338c75d382
sha256: 0f806a850507561d4e5efe13ee47b660cdf04465017a7c41fff1ccdb8d497fe6
sha512: 7ae92d49b10346a0f41491ef71776cf762f4bb5822eedcd93fb92b8d0799bd278cb15ff5901140789d2200e13be37ea9c45d24fa0a657b11e07861853dd42b92
ssdeep: 384:0zmY7Zdtis7RCngsgnXsPwCYDdmUUtEh0rnaPkgzkTB9wP7wUqMTYuw3gBBS:0PLvntnKEGEBjzq9wP7w0Tn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14FD26B0796A200EED1A3C7B9836D46434E2CBA47BBEF63DD475930572AE1958C630F36
sha3_384: e6a83e1d43f2e34bfeb1492b5f5cee56f4c9780d14cb5af04274fe704aac7f83946303f0e7a14a0fe1b776470854aef4
ep_bytes: 60be00e040008dbe0030ffff5783cdff
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: DIGERATI
FileDescription: Keygen by JeOrJe DoublePi Push Jnr.
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0407 0x04e4

Trojan.GenericPMF.S2752897 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.70127062
FireEyeGeneric.mg.5e7637badbee5478
CAT-QuickHealTrojan.GenericPMF.S2752897
SkyhighBehavesLike.Win32.ObfuscatedPoly.mh
McAfeeArtemis!5E7637BADBEE
MalwarebytesMachineLearning/Anomalous.100%
SangforPUP.Win32.Agent.Vwtm
BitDefenderThetaGen:NN.ZelphiF.36792.bmKfa0z3hWy
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderTrojan.GenericKD.70127062
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.70127062 (B)
VIPRETrojan.GenericKD.70127062
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.b.881
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Generic.D42E0DD6
GDataTrojan.GenericKD.70127062
VaristW32/KeyTroj.A.gen!Eldorado
ALYacTrojan.GenericKD.70127062
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R023H0CK423
RisingTrojan.Generic@AI.84 (RDML:Ip78yuVw8mZ662Eik5MQGA)
YandexTrojan.GenAsa!vdbFkVR+OIw
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (W)

How to remove Trojan.GenericPMF.S2752897?

Trojan.GenericPMF.S2752897 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment