Malware

Application.AdMail (A) removal instruction

Malware Removal

The Application.AdMail (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.AdMail (A) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Application.AdMail (A)?


File Info:

name: 043632DAC38DA70E7F70.mlw
path: /opt/CAPEv2/storage/binaries/0e67a9c1105c8360ae4dbf278ac1a2a3b458ae1e2d766ffbdc5e3967a633d365
crc32: E6A91140
md5: 043632dac38da70e7f70b96a2ae7b9e0
sha1: 0271be1a99e3a94164578325952a098342dbd1b5
sha256: 0e67a9c1105c8360ae4dbf278ac1a2a3b458ae1e2d766ffbdc5e3967a633d365
sha512: 8b8c854f6fe31218633090760322f8c38dcca7d428e02a3370b84ecdba03f3bb81ed93b5a3b4ee8d33ec43308f09a180f6ba325f57516885089fd4711d0ca1c9
ssdeep: 3072:DrAVguiZxHF02SOacgAf+9mzB7y7YRguXt:DWgVZ1vGAfL1X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3F38C0237C1C0B0EAE7023109B89B66997DFD714B7049D7B7984B1E6DB06D0AB36B67
sha3_384: ffdc2d2b0c5ba90889df24eace1d4d5f46729ac73b2f57eb12ab058a3a114a6ff14493d2133a563d30ce36a4de6f7fb8
ep_bytes: e8a6730000e97ffeffff558bec568b75
timestamp: 2016-09-23 08:27:17

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.9.0.1
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.9.0.1
Comments:
Translation: 0x0409 0x04b0

Application.AdMail (A) also known as:

Elasticmalicious (high confidence)
DrWebAdware.Downware.17838
MicroWorld-eScanApplication.Agent.BOI
FireEyeApplication.Agent.BOI
CAT-QuickHealPUA.MailRu.S232696
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 004fffcd1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/S-e83a6442!Eldorado
ESET-NOD32a variant of Win32/MailRu.R potentially unwanted
ClamAVWin.Malware.Mailru-6804211-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderApplication.Agent.BOI
SUPERAntiSpywarePUP.MailRU/Variant
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareApplication.Agent.BOI
SophosMail.ru Downloader (PUA)
ComodoApplication.Win32.MailRu.EC@6mwxfg
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftApplication.AdMail (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.MailRu.A
JiangminAdWare.Machaer.bm
MAXmalware (ai score=75)
Antiy-AVLTrojan/Generic.ASBOL.A8F1
ViRobotTrojan.Win32.Agent.158352
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.MailRu.X2108
VBA32Adware.Downware
ALYacApplication.Agent.BOI
MalwarebytesPUP.Optional.RussAd
RisingPUF.MailRu!1.A9B5 (CLASSIC)
YandexRiskware.Agent!l+wV+lSL8Kg
IkarusPUA.MailRu
eGambitUnsafe.AI_Score_99%
FortinetW32/MailRu.M!tr
Cybereasonmalicious.ac38da
MaxSecureTrojan.Malware.121218.susgen

How to remove Application.AdMail (A)?

Application.AdMail (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment