PUA

PUA.IcloaderPMF.S19636164 information

Malware Removal

The PUA.IcloaderPMF.S19636164 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.IcloaderPMF.S19636164 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine PUA.IcloaderPMF.S19636164?


File Info:

crc32: DCD6162A
md5: d6bb2879d5de116e3dee26f796206fc5
name: D6BB2879D5DE116E3DEE26F796206FC5.mlw
sha1: 18efedb7f766236221bc2adc8fce07a8ae8c62e9
sha256: 1a313e4eb7d194a1e3a7f28647fb2182a6737551f1f5a2d590bc81e38940d3fe
sha512: c1751d70e9d2909973aba76341c121fe7cfd563f754774804e8dc43ee39cdf49d55a5588d3c26e5706896ee55c5db5b5bbf2f454cdffc0bdef2fd4b4600e54fb
ssdeep: 49152:1i3A98ZtHA2IV0chPGct4yu5eVhaAk+lR:1i3bZtZI2KPGctxBlf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUA.IcloaderPMF.S19636164 also known as:

K7AntiVirusTrojan ( 00528e7f1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2662
MicroWorld-eScanGen:Variant.Zusy.398343
CAT-QuickHealPUA.IcloaderPMF.S19636164
ALYacGen:Variant.Zusy.398343
CylanceUnsafe
ZillyaAdware.FileTour.Win32.33364
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaAdWare:Win32/Katusha.70f1292a
K7GWTrojan ( 00525a491 )
Cybereasonmalicious.9d5de1
CyrenW32/S-af6d87b4!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GCPJ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Zusy.398343
NANO-AntivirusRiskware.Win32.ICLoader.exlqzx
Ad-AwareGen:Variant.Zusy.398343
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GCO@7hwoq2
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
McAfee-GW-EditionPacked-VJ!D6BB2879D5DE
FireEyeGeneric.mg.d6bb2879d5de116e
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.FileTour.hfi
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.244D17B
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitTrojan.Zusy.D61407
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataGen:Variant.Zusy.398343
AhnLab-V3PUP/Win32.ICLoader.R219807
Acronissuspicious
McAfeePacked-VJ!D6BB2879D5DE
MAXmalware (ai score=86)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.1149200f
YandexTrojan.GenAsa!hawjt5MU2GE
IkarusPUA.Win32.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove PUA.IcloaderPMF.S19636164?

PUA.IcloaderPMF.S19636164 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment