Trojan

Trojan.GenericPMF.S30132569 removal guide

Malware Removal

The Trojan.GenericPMF.S30132569 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S30132569 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.GenericPMF.S30132569?


File Info:

name: 5D2AE2259F357CF0A7AB.mlw
path: /opt/CAPEv2/storage/binaries/b9cdd13a88a934c191f097da315f9047029ba668b7d5d9e4c4daa060741720fb
crc32: ACE41568
md5: 5d2ae2259f357cf0a7abed8d6c5df12b
sha1: 4b2a4a2163ff13c3f4495c10f2a9b37ea7357e82
sha256: b9cdd13a88a934c191f097da315f9047029ba668b7d5d9e4c4daa060741720fb
sha512: 63b592835bf865b7aa4fddbb98807fdf78c3db00d35bfb8531a629d4d109e9aefbe9f29d1ce9da816a610a3a8f0ad13626ffae5ce4e1e2b67d76dc9e2584337f
ssdeep: 1536:zmDc/pULCHdf0T19yyX0tH28JZveKb7ucKoqII:yD/LxB9yyX0ECveG3KoBI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AF3A379E7D1D852DC2B413D49E2A3E3AC95FC25D24E9A97FE80B74F8831D50EE14A02
sha3_384: 2f66ec70268a99158f806d63f89223f35e35c81252b90055eb88522356be676c33c07c765c5fa8103c21048ca7c1797f
ep_bytes: 558bec6aff6870614000686039400064
timestamp: 2017-05-04 13:36:19

Version Info:

Comments: Mlhello
CompanyName: OMFG
FileDescription: Clien Local RunProcess
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: Mlhello
LegalCopyright: All rights reserved.
LegalTrademarks: Mlhello
OriginalFilename: Mlhello
PrivateBuild: Mlhello
ProductName: OMFG® Operating System
ProductVersion: 17.000.14393.08
SpecialBuild:
Translation: 0x0409 0x04b0

Trojan.GenericPMF.S30132569 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanDropped:Generic.Dacic.DED21A61.A.C17632E8
ClamAVWin.Trojan.Nitol-6335025-0
FireEyeGeneric.mg.5d2ae2259f357cf0
CAT-QuickHealTrojan.GenericPMF.S30132569
ALYacDropped:Generic.Dacic.DED21A61.A.C17632E8
MalwarebytesGeneric.Trojan.ServStart.DDS
ZillyaTrojan.ServStart.Win32.25615
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.59f357
BaiduWin32.Trojan.ServStart.as
CyrenW32/Heuristic-114!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/ServStart.IK
ZonerTrojan.Win32.126837
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-DDoS.Win32.Nitol.gen
BitDefenderDropped:Generic.Dacic.DED21A61.A.C17632E8
NANO-AntivirusTrojan.Win32.GenKryptik.fnpxyy
SUPERAntiSpywareTrojan.Agent/Gen-Nitol
AvastWin32:Nitol-B [Trj]
TencentTrojan-DdoS.Win32.Nitol.wa
EmsisoftDropped:Generic.Dacic.DED21A61.A.C17632E8 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen5
DrWebTrojan.DownLoader24.51669
VIPREDropped:Generic.Dacic.DED21A61.A.C17632E8
TrendMicroTROJ_NITOL.SMN1
McAfee-GW-EditionBehavesLike.Win32.Trojan.cz
Trapminemalicious.high.ml.score
SophosTroj/Nitol-BF
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.1J91XNC
JiangminTrojan.Generic.bhzka
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen5
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
ArcabitGeneric.Dacic.DED21A61.A.C17632E8
ZoneAlarmVHO:Trojan-DDoS.Win32.Nitol.gen
MicrosoftDDoS:Win32/Nitol!atmnm
GoogleDetected
AhnLab-V3Trojan/Win.Nitol.R457472
McAfeeTrojan-FOGN!5D2AE2259F35
MAXmalware (ai score=83)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_NITOL.SMN1
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
YandexTrojan.GenAsa!DM1KURgoIaA
IkarusTrojan.Win32.ServStart
MaxSecureTrojan.Malware.121218.susgen
FortinetMalwThreat!E1E6IV
BitDefenderThetaGen:NN.ZexaF.36318.jm1@airZkOaj
AVGWin32:Nitol-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.GenericPMF.S30132569?

Trojan.GenericPMF.S30132569 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment