PUA

PUA.IGENERICPMF.S2341601 removal instruction

Malware Removal

The PUA.IGENERICPMF.S2341601 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.IGENERICPMF.S2341601 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUA.IGENERICPMF.S2341601?


File Info:

name: 1CA58148BB9A1AF3DE82.mlw
path: /opt/CAPEv2/storage/binaries/5908e1a62b38f06092c74650627f25301856d1fb0d3b4b6d9bd2f5fb254f1f27
crc32: D4F71F56
md5: 1ca58148bb9a1af3de82507132bee0fc
sha1: 71128d0ee73998a5e4ca27455b9faad73dca1323
sha256: 5908e1a62b38f06092c74650627f25301856d1fb0d3b4b6d9bd2f5fb254f1f27
sha512: 4c902b3fd9393d39521e9b502efc03fcb43d19c2cbfa302d5a2902ac889263ed09bf18032ecbb83db41c4ded272e48f6e3a66342c9ef1c28b6908d83297fecdc
ssdeep: 12288:GKf5gcGbYdQEaHYxvXXizt/x44P5HAWOp2WB2PZaxnLiQtGdI888888888888W8d:JRjAYdZYYxvAt/xn5JOrAhknrtGI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133E49E32F3D14437D13366799C6B93646C2A7E202ED4A94A2EF8DD4D5F39781383A293
sha3_384: 70273cd5e47ea0431d2b4e06465f69fe242fe1c989de2dfedd35b1a13fc7674f948a25a0b50441490d795b5e64a8164f
ep_bytes: 558bec83c4f0b810df4800e82080f7ff
timestamp: 2014-09-24 21:33:07

Version Info:

0: [No Data]

PUA.IGENERICPMF.S2341601 also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
CAT-QuickHealPUA.IGENERICPMF.S2341601
McAfeeGenericR-OCX!1CA58148BB9A
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusAdware ( 005380ab1 )
AlibabaAdWare:Win32/DealPly.025f8811
K7GWAdware ( 005380ab1 )
Cybereasonmalicious.8bb9a1
VirITAdware.Win32.DealPly.EQ
CyrenW32/Trojan.BWZ.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DealPly.OT potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusRiskware.Win32.DealPly.fjsbph
ViRobotAdware.Dealply.700928.ADW
MicroWorld-eScanAdware.DealPly.1.Gen
AvastWin32:DealPly-AJ [Adw]
TencentMalware.Win32.Gencirc.114b4023
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1206819
ZillyaAdware.DealPly.Win32.110407
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.1ca58148bb9a1af3
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
GDataAdware.DealPly.1.Gen
JiangminAdWare.DealPly.hzoe
AviraHEUR/AGEN.1206819
MAXmalware (ai score=66)
ArcabitAdware.DealPly.1.Gen
SUPERAntiSpywarePUP.DealPly/Variant
MicrosoftTrojan:Win32/Occamy.C59
AhnLab-V3PUP/Win32.DealPly.R228206
BitDefenderThetaAI:Packer.6C47E72816
VBA32Adware.DealPly
MalwarebytesMalware.AI.1722302842
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
RisingAdware.DealPly!1.AA42 (CLOUD)
YandexTrojan.GenAsa!h0C8y2LAlXE
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DealPly
AVGWin32:DealPly-AJ [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUA.IGENERICPMF.S2341601?

PUA.IGENERICPMF.S2341601 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment