PUA

PUP.Optional.IWin malicious file

Malware Removal

The PUP.Optional.IWin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.IWin virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Anomalous binary characteristics

Related domains:

dl.iwin.com

How to determine PUP.Optional.IWin?


File Info:

crc32: FEBBC101
md5: cc55118f8925ba40e3930ecc99047ff6
name: CC55118F8925BA40E3930ECC99047FF6.mlw
sha1: c1cfa0865029314e187e9a6150d2d3025b9727c2
sha256: dcba5377c1ba99913862833c8f07bd55e04654f5472bdfec25b5c61742f8aad5
sha512: 3e896c0d7774f3333259cdde849c78d76d9547579eb127717abdae594f8ca7da858f1742744e004dee192f232a6ff579f28bdd2352a17a5f8d6a692c0ef61877
ssdeep: 1536:DLXB65939tY6HBg4sXJSiwhKKS20Ub2nLnVn1KxSmiwGOcVf28i2e:DLk395hYXJSiZKoHLn+x5i0+i2e
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: xa9 iWin inc.
FileVersion: 1.0.2.0
CompanyName: iWin inc.
ProductName: iWin Games
ProductVersion: 1.0.2.0
FileDescription: iWin Games Downloader
Translation: 0x0409 0x0000

PUP.Optional.IWin also known as:

K7AntiVirusAdware ( 0054f14d1 )
K7GWAdware ( 0054f14d1 )
CyrenW32/AdLoad.DB.gen!Eldorado
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
AlibabaDownloader:Win32/AdLoad.e7459532
SophosGeneric ML PUA (PUA)
AviraGAME/Downloader.Gen8
Antiy-AVLRiskWare[Downloader]/Win32.Agent.hdyt
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Generic
CynetMalicious (score: 85)
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesPUP.Optional.IWin

How to remove PUP.Optional.IWin?

PUP.Optional.IWin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment