PUA

Mail.ru Downloader (PUA) removal

Malware Removal

The Mail.ru Downloader (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mail.ru Downloader (PUA) virus can do?

  • Presents an Authenticode digital signature
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
gosoftdl.mail.ru
a.tomx.xyz

How to determine Mail.ru Downloader (PUA)?


File Info:

crc32: 5F74A363
md5: 03427554ffa8a7302b6c5e437e2c9419
name: amigo_dexp.exe
sha1: adf1d8571a1ae9aeab9dfcbee4f83f85beed2574
sha256: 522b4f0fd6063f4740369d9e17831ad3268c6ba8c41e7b67922d751ca2e493f6
sha512: 6b533df43a8e2b25a09eedee803673a3b2a6a7d0fa40cb263b1239cdd21bfc9fde7c24764be7f0f55ad55c7b01e800f68a95a1c57edb413113683ab34fdb6206
ssdeep: 3072:+5ERKdsNSE8jWf+FnGevgjFA+WzmLpJhJ4RpS:+wB8qonGeoFA0lyp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015
InternalName: launcher
FileVersion: 3.15.0.75
CompanyName: Mail.Ru
Comments:
ProductName: Mail.Ru Launcher
ProductVersion: 3.15.0.75
FileDescription: Mail.Ru Launcher
OriginalFilename: launcher.exe
Translation: 0x0409 0x04b0

Mail.ru Downloader (PUA) also known as:

DrWebAdware.Downware.19192
MicroWorld-eScanGen:Variant.Application.Agent.6
FireEyeGeneric.mg.03427554ffa8a730
CAT-QuickHealTrojan.Loadmoney
McAfeePUP-HAI
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 0054652b1 )
BitDefenderGen:Variant.Application.Agent.6
K7GWAdware ( 0054652b1 )
Cybereasonmalicious.4ffa8a
Invinceaheuristic
F-ProtW32/S-2773094c!Eldorado
APEXMalicious
AvastWin32:PUP-gen [PUP]
ClamAVWin.Malware.Mailru-6804164-0
GDataGen:Variant.Application.Agent.6
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
NANO-AntivirusRiskware.Win32.MailRu.fdukaz
Ad-AwareGen:Variant.Application.Agent.6
SophosMail.ru Downloader (PUA)
ComodoApplication.Win32.MailRu.M@7oho6u
F-SecureProgram.APPL/MailRu.B
ZillyaTool.Agent.Win32.26977
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftApplication.Downloader (A)
IkarusPUA.MailRu
CyrenW32/S-2773094c!Eldorado
JiangminAdWare.Machaer.ad
MaxSecureAdware.Adware.Machaer.gen_172020
AviraAPPL/MailRu.B
Antiy-AVLGrayWare[Adware]/Win32.Mailru.m
Endgamemalicious (high confidence)
ArcabitTrojan.Application.Agent.6
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Machaer.gen
MicrosoftPUA:Win32/LoadMoney
AhnLab-V3PUP/Win32.MailRu.R232581
VBA32BScope.Adware.Machaer
MAXmalware (ai score=73)
MalwarebytesRiskWare.Agent
ESET-NOD32a variant of Win32/MailRu.M potentially unwanted
YandexRiskware.Agent!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/MailRu.M!tr
AVGWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mail.ru Downloader (PUA)?

Mail.ru Downloader (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment