Trojan

Trojan.GenericPMF.S3224656 malicious file

Malware Removal

The Trojan.GenericPMF.S3224656 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S3224656 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system

Related domains:

static.43.47.69.159.clients.your-server.de

How to determine Trojan.GenericPMF.S3224656?


File Info:

crc32: B72238A5
md5: 0043e60d4d0087bb1c76d8a1859a86ee
name: 0043E60D4D0087BB1C76D8A1859A86EE.mlw
sha1: 1c3c42d1ef623be1d9b12528139393336b07045f
sha256: 02918f78f1c3cedcbb7baaac667862abdd69b5c64e8f248e01ad45d4df04f337
sha512: d6a9a25f5841336fe08d8ff525f50c6b5dcbc16607acc4aa83671bacb7ad3046915ebd9b02d9ba0fdc492355728410c37b4cc14a3d7b5e3712f95e93de3789ee
ssdeep: 24576:rEUJZs6W5i841Iwar7rPUoKE/tCZUu9GHhC:rE76WQp1IxUHE/oeC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: XRepair.exe
FileVersion: 14.2.1058.4
ProductName: Framework 4.5
ProductVersion: 14.2.1058.4
FileDescription: Framework 4.5 Setup
OriginalFilename: XRepair.exe
Translation: 0x0409 0x04b0

Trojan.GenericPMF.S3224656 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3664
CAT-QuickHealTrojan.GenericPMF.S3224656
ALYacApplication.Bundler.ICLoader.4.Gen
CylanceUnsafe
ZillyaTrojan.Generic.Win32.157641
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Katusha.767b9ca2
K7GWTrojan ( 0056f4471 )
K7AntiVirusTrojan ( 0056f4471 )
CyrenW32/S-f35c75bd!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GJNS
APEXMalicious
AvastWin32:AdwareSig [Adw]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.Bundler.ICLoader.4.Gen
NANO-AntivirusTrojan.Win32.InstallCube.fhmeob
MicroWorld-eScanApplication.Bundler.ICLoader.4.Gen
TencentMalware.Win32.Gencirc.10cc5229
Ad-AwareApplication.Bundler.ICLoader.4.Gen
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
TrendMicroPUA.Win32.ICLoader.SMA
FireEyeGeneric.mg.0043e60d4d0087bb
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.coqnr
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitApplication.Bundler.ICLoader.4.Gen
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataWin32.Application.ICLoader.F
AhnLab-V3PUP/Win32.ICLoader.R233555
Acronissuspicious
McAfeePacked-FHK!0043E60D4D00
MAXmalware (ai score=76)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.ICLoader.SMA
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!sTSt7DniX1E
IkarusPUA.FileTour
MaxSecureTrojan.Packed.WIN32.Katusha.gen_216069
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Trojan.GenericPMF.S3224656?

Trojan.GenericPMF.S3224656 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment