Trojan

Trojan.IgenericPMF.S25294534 removal instruction

Malware Removal

The Trojan.IgenericPMF.S25294534 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.IgenericPMF.S25294534 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Nepali
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • CAPE detected the CryptBot malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.IgenericPMF.S25294534?


File Info:

name: 4EE353AE995C1C21DC29.mlw
path: /opt/CAPEv2/storage/binaries/e8c4b26bf4620befa882016181a4f987594de2a5590ae4c94ecd9351e922cd64
crc32: 29FC7B33
md5: 4ee353ae995c1c21dc294a86e040e9cb
sha1: 218868ac69fe18abe49ae58192c09d32e61019f7
sha256: e8c4b26bf4620befa882016181a4f987594de2a5590ae4c94ecd9351e922cd64
sha512: ac99c0679769eb834094bf5fd5ad2f0c8ee95eaf80f4da5abe2676f0e7f58398770fdcb96e28ffa411069a753810018342ffdf68e112b33e986cc834ae88e793
ssdeep: 6144:rHb52mA3WmGYNInicUUfZMIBiKpnIDyJwv30:rHbkdWmGKKic5hWwIuKf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C584CF1272D1C033C04665B64926C7B19E7AB8701BA66ACF7FD84BBD5F243D1973A30A
sha3_384: 37a93ac61b0d9092608a29089f981b2b0247b330776548fac31599b662aca558fb43de0c1ab7c71d1b22f5cbb0791237
ep_bytes: e8db830000e978feffff8bff558bec83
timestamp: 2020-09-11 06:46:58

Version Info:

FileVers: 7.0.4.24
ProductVersa: 7.0.25.71
InternalName: reaLatimad
LegalCopyrighd: Jdfglsdffa
Translations: 0x0169 0x0301

Trojan.IgenericPMF.S25294534 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Convagent.l!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.10657
MicroWorld-eScanTrojan.GenericKD.38194177
FireEyeGeneric.mg.4ee353ae995c1c21
CAT-QuickHealTrojan.IgenericPMF.S25294534
ALYacTrojan.GenericKD.38194177
MalwarebytesTrojan.MalPack.GS.Generic
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058b67e1 )
AlibabaTrojanSpy:Win32/Azorult.4d445390
K7GWTrojan ( 0058b67e1 )
Cybereasonmalicious.c69fe1
BitDefenderThetaGen:NN.ZexaF.34084.yq0@aWO3ssfG
CyrenW32/Kryptik.FWZ.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HNOL
TrendMicro-HouseCallTROJ_GEN.R002C0DL821
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderTrojan.GenericKD.38194177
NANO-AntivirusTrojan.Win32.Stealer.jivwrm
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Kryptik!1.DAF8 (CLASSIC)
Ad-AwareTrojan.GenericKD.38194177
EmsisoftTrojan.Crypt (A)
ZillyaTrojan.Kryptik.Win32.3639079
TrendMicroTROJ_GEN.R002C0DL821
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosML/PE-A + Troj/Krypt-BO
IkarusTrojan.Win32.Azorult
JiangminTrojan/Obfuscated.butu
Antiy-AVLTrojan/Generic.ASCommon.215
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Azorult.RM!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataTrojan.GenericKD.38194177
SentinelOneStatic AI – Malicious PE
AhnLab-V3CoinMiner/Win.Glupteba.R456355
Acronissuspicious
McAfeeRDN/Convagent
VBA32Malware-Cryptor.2LA.gen
APEXMalicious
MAXmalware (ai score=81)
FortinetPossibleThreat.PALLAS.H
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.IgenericPMF.S25294534?

Trojan.IgenericPMF.S25294534 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment