Categories: Trojan

Trojan.GenericPMF.S4554719 removal instruction

The Trojan.GenericPMF.S4554719 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S4554719 virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.GenericPMF.S4554719?


File Info:

crc32: 277EC0B6md5: 74e8f3c59c3a09ba7a785f8712a88531name: 105-2-1-41.exesha1: 1777d7a29b4941431adc97e910da5371a32cf98fsha256: eb7cb8519accf4d61d5695790d396e3e7e705d7a4aaf2860fb0029f9222e264fsha512: ac7be215c7c8b0ce8fa84c477391f52b19139cb8ad21dd40ba389f40d319b22d74b1471d4e053d84e0eac767d51176f2fbf6c4d9c34761a876a0f6bd3e8fbadcssdeep: 1536:AvwIMUkn5lRjATpx6GWT4T/ajv31Stu/OpvKD4B/rYxoJ+zgX28DCeoUPiZ:iJknVKucT/uvFDmxKq/rCoOmoUktype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.GenericPMF.S4554719 also known as:

DrWeb Dialer.Online.2
MicroWorld-eScan Gen:Variant.Razy.43087
FireEye Generic.mg.74e8f3c59c3a09ba
CAT-QuickHeal Trojan.GenericPMF.S4554719
ALYac Gen:Variant.Razy.43087
VIPRE BehavesLike.Win32.Malware.bsc (vs)
Sangfor Malware
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Gen:Variant.Razy.43087
K7GW Riskware ( 0040eff71 )
Cybereason malicious.59c3a0
TrendMicro DIAL_RAS.HE
BitDefenderTheta Gen:NN.ZexaF.32517.fmGfaarILNF
Cyren W32/Webdialer.gen!GSA
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:Dialer-ACP [Trj]
ClamAV Win.Trojan.Dialer-202
GData Gen:Variant.Razy.43087
Kaspersky Trojan.Win32.Scar.fmke
NANO-Antivirus Trojan.Win32.Scar.exuuur
ViRobot Trojan.Win32.A.Scar.62513[UPX]
Rising HackTool.PornDialer!1.6613 (CLASSIC)
Ad-Aware Gen:Variant.Razy.43087
Sophos Dial/190-A
Comodo ApplicUnsaf.Win32.Dialer.Generic@jux8x
F-Secure Dialer.DIAL/000293
Zillya Trojan.Scar.Win32.72351
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Dropper.nc
Trapmine malicious.moderate.ml.score
Emsisoft Gen:Variant.Razy.43087 (B)
Ikarus Dialer
F-Prot W32/Webdialer.gen!GSA
Jiangmin Trojan/Generic.bfcl
Avira DIAL/000293
Endgame malicious (high confidence)
Arcabit Trojan.Razy.DA84F
ZoneAlarm Trojan.Win32.Scar.fmke
Microsoft Dialer:Win32/Webdialer
AhnLab-V3 Adware/Win32.Dialer.R21773
Acronis suspicious
McAfee Dialer-RAS.a.gen
MAX malware (ai score=88)
VBA32 Trojan.Scar
Cylance Unsafe
Panda Generic Malware
ESET-NOD32 a variant of Win32/Dialer.0190-Dialers
TrendMicro-HouseCall DIAL_RAS.HE
Yandex Dialer.eConnect.Gen
SentinelOne DFI – Suspicious PE
AVG Win32:Dialer-ACP [Trj]
CrowdStrike win/malicious_confidence_60% (W)

How to remove Trojan.GenericPMF.S4554719?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Trojan:Win32/Mdrop.A”?

The Trojan:Win32/Mdrop.A is considered dangerous by lots of security experts. When this infection is active,…

58 seconds ago

What is “Malware.AI.94122528”?

The Malware.AI.94122528 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Win32/VBObfus.Y malicious file

The Win32/VBObfus.Y is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Application.Bundler.Morstar.30 removal guide

The Application.Bundler.Morstar.30 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

How to remove “Trojan:Win32/Bohmini!pz”?

The Trojan:Win32/Bohmini!pz is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

How to remove “Worm.Win32.Vobfus.efkf”?

The Worm.Win32.Vobfus.efkf is considered dangerous by lots of security experts. When this infection is active,…

32 mins ago