Trojan

Trojan.ScriptPMF.S17266616 removal tips

Malware Removal

The Trojan.ScriptPMF.S17266616 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptPMF.S17266616 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rem-pounds.ddns.net

How to determine Trojan.ScriptPMF.S17266616?


File Info:

crc32: 67DA0A7E
md5: 4ef0b19d80d49f883b79af15401db5de
name: 4EF0B19D80D49F883B79AF15401DB5DE.mlw
sha1: 73cda6de1c84d9013f05c3abac02b510e2548989
sha256: 62c6c6aa0032b0b672a94d25a5f6d453783dc9d52391ca047469381d7650c7c8
sha512: 76252c733d4709351a4db0f57ea577b7c78e60369197acb011c559003ca554f14f39ee539f8a2b867fc62eb111b9fddfb19194c5839697eabe37cc39a71e55a7
ssdeep: 24576:YEfUzt0WsNtypnSHZNTZ5kB3z0mHaYfltT5Uf1te:LUztHpS55C3QYaClnG1A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: appsruprov
FileVersion: 539.779.771.83
CompanyName: SystemPropertiesProtection
ProductName: AppManagementConfiguration
ProductVersion: 58.935.541.746
FileDescription: vsjitdebugger
OriginalFilename: TpmInit
Translation: 0x0409 0x04b0

Trojan.ScriptPMF.S17266616 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Malware.Nymeria-6993200-0
CAT-QuickHealTrojan.ScriptPMF.S17266616
ALYacTrojan.GenericKD.35980570
CylanceUnsafe
ZillyaTrojan.AutoItScript.Win32.44
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AutoIt.QE
ZonerTrojan.Win32.100444
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Convagent.gen
MicroWorld-eScanTrojan.GenericKD.35980570
TencentMalware.Win32.Gencirc.10ce2aaa
Ad-AwareTrojan.GenericKD.35980570
SophosML/PE-A + Troj/AutoIt-DAW
DrWebTrojan.DownLoader28.40437
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.4ef0b19d80d49f88
EmsisoftTrojan.GenericKD.35980570 (B)
AviraHEUR/AGEN.1100064
MicrosoftTrojan:Win32/Remcos.AUT!MTB
GridinsoftTrojan.Win32.Downloader.oa!s1
ArcabitTrojan.Generic.D225051A
ZoneAlarmTrojan.Script.Obit.gen
GDataTrojan.GenericKD.35980570
AhnLab-V3Trojan/Win32.RL_AutoInj.R272810
Acronissuspicious
McAfeeAutoIt/Injector.ax
MAXmalware (ai score=86)
MalwarebytesBladabindi.Backdoor.Njrat.DDS
PandaTrj/Genetic.gen
RisingTrojan.Injector/Autoit!1.BB8F (CLASSIC)
IkarusTrojan.Autoit
MaxSecureWin.MxResIcn.Heur.Gen
FortinetAutoIt/Injector.EKY!tr
AVGAutoIt:Injector-JF [Trj]

How to remove Trojan.ScriptPMF.S17266616?

Trojan.ScriptPMF.S17266616 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment