PUA

PUA.IgenericIH.S27064394 removal tips

Malware Removal

The PUA.IgenericIH.S27064394 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.IgenericIH.S27064394 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine PUA.IgenericIH.S27064394?


File Info:

name: CE6293958A4BD7E79CD1.mlw
path: /opt/CAPEv2/storage/binaries/eb7bc232dfb3bd40d776e58a5192aaafa2efacfba3906706b54a44927dece4d3
crc32: 8DF89E42
md5: ce6293958a4bd7e79cd1a39ecdfd923c
sha1: 7b3e556be8b09c97bb63728185e750a62084bf94
sha256: eb7bc232dfb3bd40d776e58a5192aaafa2efacfba3906706b54a44927dece4d3
sha512: da767dc1f9a49fba16f981ea02fe1ca6047b8a506669c7c6e0bedf455fe5bcfcbc9ed812cb8357084dc25039a0c592cee72f2587866aacfe9224eddd699d8103
ssdeep: 24576:Qak/7Nk4RZ68nGNPKZu0zoFmDcpii9iGn+66rLfJIgtEqPILWz8oDqE:Qak/U8nvZu+k0WdEacJRIo+E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF55231927CCBB99E70673785172BF2596A27370BC82D6B7B324EC543D0B02ADD14A93
sha3_384: d8958b89401aa9dd4a60186157550a7a0da3ba66c26756edd61d327309728a21e4c12e0b633e3d96282ca20f5cb9ed26
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2022-03-23 11:36:58

Version Info:

CompanyName: 178网游工作室
FileDescription: 商业程序
InternalName: LoginTools.exe
LegalCopyright: 版权所有 (C) 2010
OriginalFilename: LoginTools.exe
ProductName: 商业程序
ProductVersion: 1, 0, 0, 0
FileVersion: 1,0,0,0
Translation: 0x0804 0x03a8

PUA.IgenericIH.S27064394 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.134753
FireEyeGeneric.mg.ce6293958a4bd7e7
CAT-QuickHealPUA.IgenericIH.S27064394
ALYacGen:Variant.Bulz.134753
CylanceUnsafe
K7AntiVirusRiskware ( 005439d61 )
K7GWRiskware ( 005439d61 )
Cybereasonmalicious.58a4bd
BitDefenderThetaGen:NN.ZelphiF.34742.qT0baO4tUhci
CyrenW32/Bulz.V.gen!Eldorado
ESET-NOD32a variant of Win32/RiskWare.GameTool.S
BitDefenderGen:Variant.Bulz.134753
AvastWin32:Malware-gen
TencentRiskWare.Win32.GameTool.ha
Ad-AwareGen:Variant.Bulz.134753
SophosGeneric ML PUA (PUA)
DrWebTrojan.DownLoader44.47791
ZillyaTool.GameTool.Win32.870
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Bulz.134753 (B)
APEXMalicious
GDataWin32.Trojan.PSE.1HJ0IZ0
JiangminTrojan.Bulz.h
AviraHEUR/AGEN.1214757
MAXmalware (ai score=83)
ArcabitTrojan.Bulz.D20E61
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R329115
McAfeeGenericRXAA-AA!CE6293958A4B
VBA32TScope.Trojan.Delf
MalwarebytesRiskWare.GameTool
RisingMalware.Lmir!8.E96A (CLOUD)
YandexTrojan.GenAsa!8M74xrHXt8Q
IkarusTrojan.ManBat
MaxSecureTrojan.Malware.109381195.susgen
FortinetRiskware/GameTool
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUA.IgenericIH.S27064394?

PUA.IgenericIH.S27064394 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment