PUA

PUA.UwamsonRI.S27872074 removal guide

Malware Removal

The PUA.UwamsonRI.S27872074 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.UwamsonRI.S27872074 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Suspicious wmic.exe use was detected

How to determine PUA.UwamsonRI.S27872074?


File Info:

name: E7842A37A8FA37805DCF.mlw
path: /opt/CAPEv2/storage/binaries/4743ddeb97c28f62ad6b80669e12e98173a4f3d78f1343e1baeb904eb8c7a201
crc32: 65B8686A
md5: e7842a37a8fa37805dcf9bbfbd3c4002
sha1: 0f7af12740338e8b0edcd15168143fd3e40cb229
sha256: 4743ddeb97c28f62ad6b80669e12e98173a4f3d78f1343e1baeb904eb8c7a201
sha512: a4cdb7245ed6db422eb2b34f636e2a2f663ae416915b54fac3097b0548c7f5bddc46f19ade0443250aaef644f567c3c133a14bbb04206f36cb5530cd5e138d61
ssdeep: 49152:aZFIlmhRYg1OziGQGRCv6da/KMvxZdAMBwQoxXXujOl4MPMFvfldPSFrXxn3x:1l7i86hR+fWMeP43x
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1C3D57C51A7A800E8D9B7C278C9528517D7F2F81523719BDF06A44ABA0F23AE12F3F715
sha3_384: 1aeaf1fa85f7d9e9ba3091556202c8bc1c7210ae12b4df4cf9b01b36c241532a48420429d59b20362549d2b334786243
ep_bytes: 4883ec28e8630500004883c428e976fe
timestamp: 2021-02-07 23:55:58

Version Info:

FileDescription: Mesh Agent Service
FileVersion: 0.2.1.3
InternalName: MeshAgent
LegalCopyright: Apache 2.0 License
OriginalFilename: MeshAgent.exe
ProductName: Mesh Agent Service
ProductVersion: 0, 0, 0, 0
Translation: 0x0409 0x04b0

PUA.UwamsonRI.S27872074 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.66135193
FireEyeGeneric.mg.e7842a37a8fa3780
CAT-QuickHealPUA.UwamsonRI.S27872074
McAfeeArtemis!E7842A37A8FA
Cylanceunsafe
ZillyaTool.MeshAgent.Win32.119
SangforTrojan.Win32.Save.a
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.66135193
EmsisoftTrojan.GenericKD.66135193 (B)
VIPRETrojan.GenericKD.66135193
McAfee-GW-EditionArtemis!PUP
SophosGeneric ML PUA (PUA)
GDataTrojan.GenericKD.66135193
JiangminRemoteAdmin.MeshAgent.ca
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Generic.D3F12499
ALYacTrojan.GenericKD.66135193
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H09CU23
RisingHacktool.MeshAgent!8.13A31 (CLOUD)
MaxSecureTrojan.Malware.204987536.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove PUA.UwamsonRI.S27872074?

PUA.UwamsonRI.S27872074 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment