Trojan

Trojan.IgenericPMF.S25745021 removal

Malware Removal

The Trojan.IgenericPMF.S25745021 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.IgenericPMF.S25745021 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Icelandic
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan.IgenericPMF.S25745021?


File Info:

name: 03E4F7EDD8A65424C8AD.mlw
path: /opt/CAPEv2/storage/binaries/03de218446fa620a7e24b24795bcda3c80345e6bc059273b524c9e6bfa473c06
crc32: 0440E6E5
md5: 03e4f7edd8a65424c8adf27069f37b24
sha1: 69d0ab498a0926feed11c0ff7ff8a63d6c5cc00f
sha256: 03de218446fa620a7e24b24795bcda3c80345e6bc059273b524c9e6bfa473c06
sha512: 0a42db8cf70a1e6af45f99ea9f0a91fc5f82fb3b7028ae469d53037f0c6a87ffee5694969da1d2ba012d4d1298113bfe0cd0facf352ad5c5a8f8287590647b7b
ssdeep: 6144:+vebYHNTVglwVAKPasIPBcaDutjLuiMujs35clvb7ITsqA:+G+lkTMasMcgos5i7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12164E1D276E2F532C9E63D3148248AB54E3FB862DA31410B37751F9E6F726D19A31322
sha3_384: fe393313ba7936ec72ce3a484c56fa5844716d511a124468d513508846c1d12ac4858223894fb872ccdb0ad58316a317
ep_bytes: e8a3370000e978feffffcccccccccccc
timestamp: 2020-08-19 02:33:19

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 23.54.77.27
Translation: 0x0127 0x046a

Trojan.IgenericPMF.S25745021 also known as:

LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.8307
CynetMalicious (score: 100)
FireEyeGeneric.mg.03e4f7edd8a65424
CAT-QuickHealTrojan.IgenericPMF.S25745021
ALYacTrojan.GenericKD.38260081
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Azorult.4f64e486
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.98a092
BitDefenderThetaGen:NN.ZexaF.34160.uu0@aKx5vChG
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNQQ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tepfer-9916200-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.38260081
MicroWorld-eScanTrojan.GenericKD.38260081
AvastWin32:Trojan-gen
TencentTrojan-Spy.Win32.Stealer.16000121
Ad-AwareTrojan.GenericKD.38260081
EmsisoftTrojan.Crypt (A)
ZillyaTrojan.Kryptik.Win32.3651821
TrendMicroTROJ_GEN.R049C0DLF21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-R + Mal/Agent-AWV
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.13HWNF8
JiangminTrojanSpy.Stealer.ksa
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.STOP.sa
MicrosoftTrojan:Win32/Azorult.RM!MTB
AhnLab-V3Downloader/Win.BeamWinHTTP.R458159
Acronissuspicious
McAfeePacked-GEE!03E4F7EDD8A6
VBA32BScope.TrojanSpy.Convagent
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R049C0DLF21
RisingTrojan.Convagent!8.12323 (CLOUD)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.IgenericPMF.S25745021?

Trojan.IgenericPMF.S25745021 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment