Trojan

Trojan.LoyeetroPMF.S12575524 removal guide

Malware Removal

The Trojan.LoyeetroPMF.S12575524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.LoyeetroPMF.S12575524 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

needforrat.hopto.org

How to determine Trojan.LoyeetroPMF.S12575524?


File Info:

crc32: AFA31637
md5: 3a1db70b49e9be3303890cb7855f2296
name: 3A1DB70B49E9BE3303890CB7855F2296.mlw
sha1: fed77876af92c2eb080251ba7a3532a154be1e94
sha256: 3ffbccaf9efde195e47803fbeefbeea8daa46b8befe87b7781434c50b79d613b
sha512: 052e7cfc998eb8a6133cedb094ce7181461875031f7c7fafc1cf468d36d9d72d02705becd79c3e1e595ce02c4ba85d7baf45b0bc3125113a5a07d5b62dc3483e
ssdeep: 3072:uIka2uf1M8ddvzEGX0uLxZrzpeJAiOHLgI29a1QYMtUMqqDBPTPMFX:uIV2uddddvzEGX0uLxZrteiUrkQzt3q
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.LoyeetroPMF.S12575524 also known as:

K7AntiVirusTrojan ( 005485311 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.61502
CynetMalicious (score: 100)
CAT-QuickHealTrojan.LoyeetroPMF.S12575524
ALYacGen:Variant.Razy.684266
CylanceUnsafe
SangforBackdoor.Win32.NetWiredRC.vho
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:MSIL/NetWire.e1e3af92
K7GWTrojan ( 005485311 )
Cybereasonmalicious.b49e9b
SymantecInfostealer
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
APEXMalicious
KasperskyHEUR:Backdoor.Win32.NetWiredRC.vho
BitDefenderGen:Variant.Razy.684266
NANO-AntivirusTrojan.Win32.NetWire.hxomja
MicroWorld-eScanGen:Variant.Razy.684266
Ad-AwareGen:Variant.Razy.684266
SophosMal/Generic-S
BitDefenderThetaAI:Packer.64EFC4A51E
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.3a1db70b49e9be33
EmsisoftGen:Variant.Razy.684266 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.NetWire.vq
AviraTR/AD.NetWiredRc.BH
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Generic.ASMalwS.30F2A8C
GridinsoftTrojan.Win32.Downloader.oa!s1
GDataWin32.Trojan.Netwire.C
TACHYONTrojan/W32.NetWiredRC.176640
AhnLab-V3Trojan/Win32.RL_NetWiredRC.R354062
McAfeePWS-FCRP!3A1DB70B49E9
MAXmalware (ai score=100)
VBA32Backdoor.NetWiredRC
MalwarebytesTrojan.AutoRun
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDK21
RisingBackdoor.NetWire!1.C98D (CLASSIC)
YandexTrojan.NetWire!j5OgmYq2j9g
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Weecnaw.P!tr.spy
AVGWin32:RATX-gen [Trj]

How to remove Trojan.LoyeetroPMF.S12575524?

Trojan.LoyeetroPMF.S12575524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment