Trojan

Trojan.GenericPMF.S30424795 removal tips

Malware Removal

The Trojan.GenericPMF.S30424795 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S30424795 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.GenericPMF.S30424795?


File Info:

name: C942BC2334709B47EEF3.mlw
path: /opt/CAPEv2/storage/binaries/65733e362aaaf851b4a824873ca8114cf969aca1544c9dc062070a9fce964867
crc32: 65DAEB2F
md5: c942bc2334709b47eef3e5a8cab5db2f
sha1: 46c02a295cdee3b4401ce1bd284b546901f4f74c
sha256: 65733e362aaaf851b4a824873ca8114cf969aca1544c9dc062070a9fce964867
sha512: 996c3d5b1d2659a97fa8727621e2a1507e586646108839ca8510d0fbf307f159b64f89ad19ad0d2dd769cdd3861118771dafbbdd11f3e5014afcb17980cf1f60
ssdeep: 49152:HkduHGxAUu1QMjFetdnWIW45wRBfu73HGYeRqhZxpwzGdnHysIVT+4mA1zew4Cit:KAmdSu7FdH0VTVlE5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T167060102244CAE6FD436397563DC15A3F96C9471DB1A1D4522D2AEEFC88CE83F6A24DC
sha3_384: ec44e6d1258178a50d54d0bece429c2c40aff61e557bf5f231896123503a4c503bdb7d18e69fccfd14e33cd609812a35
ep_bytes: e8e2020000e974feffff558bec83ec0c
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: Wissol Petreleum Georgia
FileDescription: Wissol Petreleum Georgia Product
FileVersion: 877
InternalName: RP8fe8cSwLZr
LegalCopyright: © Wissol Petreleum Georgia All rights reserved.
LegalTrademarks: © Wissol Petreleum Georgia Trademarks
OriginalFilename: e0K1FNp8.exe
ProductName: GLl8Lox6pF
ProductVersion: 877
Translation: 0x0407 0x04b0

Trojan.GenericPMF.S30424795 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
DrWebTrojan.Siggen21.5312
MicroWorld-eScanTrojan.GenericKD.68000148
ClamAVWin.Malware.Dacic-10006009-0
FireEyeTrojan.GenericKD.68000148
CAT-QuickHealTrojan.GenericPMF.S30424795
ALYacTrojan.GenericKD.68000148
MalwarebytesTrojan.MalPack
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a7ab71 )
AlibabaTrojanSpy:Win32/Stealer.bbbcf7ec
K7GWTrojan ( 005a7ab71 )
VirITTrojan.Win32.Genus.RUO
CyrenW32/Kryptik.KDE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTZZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.68000148
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf04e5
EmsisoftTrojan.GenericKD.68000148 (B)
F-SecureTrojan.TR/Kryptik.hikou
VIPRETrojan.GenericKD.68000148
TrendMicroTrojan.Win32.AMADEY.YXDGFZ
McAfee-GW-EditionGenericRXWF-GF!C942BC233470
Trapminemalicious.moderate.ml.score
SophosTroj/Krypt-AAI
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Kryptik.TI
WebrootW32.Trojan.Gen
AviraTR/Kryptik.hikou
Antiy-AVLTrojan/Win32.GenKryptik
XcitiumMalware@#2wmht47bw8dva
ArcabitTrojan.Generic.D40D9994
ViRobotTrojan.Win.Z.Kryptik.3791688
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Redlinestealer!ic
GoogleDetected
AhnLab-V3Trojan/Win.REDLINESTEALER.R589955
McAfeeGenericRXWF-GF!C942BC233470
MAXmalware (ai score=81)
VBA32TrojanDownloader.Deyma
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.AMADEY.YXDGFZ
RisingTrojan.ShellCodeRunner!1.E830 (CLASSIC)
IkarusTrojan.Win32.Redline
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/GenKryptik.GLDD!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.GenericPMF.S30424795?

Trojan.GenericPMF.S30424795 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment