Trojan

Trojan.IGENERICPMF.S1948739 removal

Malware Removal

The Trojan.IGENERICPMF.S1948739 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.IGENERICPMF.S1948739 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.IGENERICPMF.S1948739?


File Info:

crc32: A49AF1AB
md5: 3a8897da697975e980579b5dbfabfcec
name: 3A8897DA697975E980579B5DBFABFCEC.mlw
sha1: b825fdc5709d18fb9560950619f75bfd2bf4e0db
sha256: 2c7bd11fe54dcd9bc339bc5615f66c8c26dd0def3ae3ac1959dd2725535f21cc
sha512: 53a56d25a13942506a80dfbd762def145a87ed0a9920d10b84dffa92e2f8b3a9f2724a3511aa05e2afce5b839d06fa619c07f02afe8c6eb527921d914b00be52
ssdeep: 12288:peqxTvay5tkmct0LHVfITnojRa3LiLuw2hXyUDIBn:fjvtkmct0LHSjERqLhXIBn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Bula
FileVersion: 3.4.31.70
CompanyName: Lepemi
LegalTrademarks:
ProductName: Kedamosoh 12 Kefasumor
ProductVersion: 3.5.47.38
FileDescription:
OriginalFilename: Bula.exe
Translation: 0x0409 0x04b0

Trojan.IGENERICPMF.S1948739 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005393151 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.IGENERICPMF.S1948739
CylanceUnsafe
ZillyaTool.Bundler.Win32.6498
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 005393151 )
Cybereasonmalicious.a69797
CyrenW32/DealPly.U.gen!Eldorado
ESET-NOD32a variant of Win32/DealPly.WC potentially unwanted
APEXMalicious
AvastWin32:DealPly-AJ [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentMalware.Win32.Gencirc.10b25232
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#12yhkox5zb7vz
BitDefenderThetaGen:NN.ZelphiF.34170.HK0@aWkLt!ki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareDealPly.hh
FireEyeGeneric.mg.3a8897da697975e9
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.mcxf
AviraHEUR/AGEN.1125473
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.249EC5E
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywarePUP.DealPly/Variant
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C2387994
Acronissuspicious
McAfeeDealPly
MAXmalware (ai score=100)
VBA32Adware.DealPly
MalwarebytesPUP.Optional.WinYahoo
PandaTrj/GdSda.A
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
FortinetAdware/Generic
AVGWin32:DealPly-AJ [Adw]
Paloaltogeneric.ml

How to remove Trojan.IGENERICPMF.S1948739?

Trojan.IGENERICPMF.S1948739 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment