Malware

What is “AdWare.Win32.Machaer”?

Malware Removal

The AdWare.Win32.Machaer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Machaer virus can do?

  • Presents an Authenticode digital signature
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

Related domains:

gosoftdl.mail.ru

How to determine AdWare.Win32.Machaer?


File Info:

crc32: 59AD0FF9
md5: 56d9225eabcb04f4dd4300f92e03af7b
name: amigo_dexp.exe
sha1: e1160c4f493b8088919615cb67ba5ecb4a94e263
sha256: 6e4b96b6d8997bb1449cf576a9051d85fb4c981c8a35310a7a6fb9d14633ade4
sha512: c1829413e855e8aa05d24603a966fcb267c926d392fa96e2ef8a344d4ebbfb004fd08a2544eb170e7c457453f6c87686bb6579290b45fa641526965ec096f132
ssdeep: 3072:+5ERKdsNSE8jWf+FnGevgjFA+WzmLpJhJ4RpS:+wB8qonGeoFA0lyp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015
InternalName: launcher
FileVersion: 3.15.0.75
CompanyName: Mail.Ru
Comments:
ProductName: Mail.Ru Launcher
ProductVersion: 3.15.0.75
FileDescription: Mail.Ru Launcher
OriginalFilename: launcher.exe
Translation: 0x0409 0x04b0

AdWare.Win32.Machaer also known as:

MicroWorld-eScanGen:Variant.Application.Agent.6
FireEyeGeneric.mg.56d9225eabcb04f4
CAT-QuickHealTrojan.Loadmoney
McAfeePUP-HAI
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Application.Agent.6
K7GWAdware ( 0054652b1 )
K7AntiVirusAdware ( 0054652b1 )
F-ProtW32/S-2773094c!Eldorado
APEXMalicious
ClamAVWin.Malware.Mailru-6804164-0
GDataGen:Variant.Application.Agent.6
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
NANO-AntivirusRiskware.Win32.MailRu.fdukaz
AvastWin32:PUP-gen [PUP]
Endgamemalicious (high confidence)
SophosMail.ru Downloader (PUA)
ComodoApplication.Win32.MailRu.M@7oho6u
DrWebAdware.Downware.19192
ZillyaTool.Agent.Win32.26977
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftApplication.Downloader (A)
IkarusPUA.MailRu
CyrenW32/S-2773094c!Eldorado
JiangminAdWare.Machaer.ad
AviraAPPL/MailRu.B
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=75)
Antiy-AVLGrayWare[Adware]/Win32.Mailru.m
MicrosoftPUA:Win32/LoadMoney
ArcabitTrojan.Application.Agent.6
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Machaer.gen
AhnLab-V3PUP/Win32.MailRu.R232581
VBA32BScope.Adware.Machaer
Ad-AwareGen:Variant.Application.Agent.6
MalwarebytesRiskWare.Agent
ESET-NOD32a variant of Win32/MailRu.M potentially unwanted
YandexRiskware.Agent!
SentinelOneDFI – Suspicious PE
MaxSecureAdware.Adware.Machaer.gen_172020
FortinetW32/MailRu.M!tr
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.eabcb0

How to remove AdWare.Win32.Machaer?

AdWare.Win32.Machaer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment