PUA

How to remove “PUA.AgentPMF.S24894518”?

Malware Removal

The PUA.AgentPMF.S24894518 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentPMF.S24894518 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine PUA.AgentPMF.S24894518?


File Info:

name: CF13223978ACCB5B36F0.mlw
path: /opt/CAPEv2/storage/binaries/512ad13e566c83b54fa5da95e97b82ccecdb85172c594188d6535de478debaea
crc32: 2F335B64
md5: cf13223978accb5b36f05f15310adc7a
sha1: 52458277816533fe6195fcc51b3ffe03344998fa
sha256: 512ad13e566c83b54fa5da95e97b82ccecdb85172c594188d6535de478debaea
sha512: 106abd1f8e33c3a12c88c359b0ddeb08c9abd49300ea2fc7f2c7a54fc277e54bb928df046655e2473648a0447c025af5eb4f70c92018ac96eb11b4e8ba13b67b
ssdeep: 3072:DrAVguiZxHF02SOacgAf+9mzB7y7YRguXt:DWgVZ1vGAfL1X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131F38C0237C1C0B0EAE7023109B89B66597DFD714BB049D7B7984B4E6DB06D0AB36B67
sha3_384: fb07a535ecb333afa53f2eca5f6cde7ab38095255d870c0fbead6a6fd8269230d3edb8e1879d6a17badc3decde893247
ep_bytes: e8a6730000e97ffeffff558bec568b75
timestamp: 2016-09-23 08:27:17

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.9.0.1
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.9.0.1
Comments:
Translation: 0x0409 0x04b0

PUA.AgentPMF.S24894518 also known as:

Elasticmalicious (high confidence)
DrWebAdware.Downware.17838
MicroWorld-eScanApplication.Agent.BOI
FireEyeApplication.Agent.BOI
CAT-QuickHealPUA.AgentPMF.S24894518
McAfeePUP-FYD
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 004fffcd1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.978acc
CyrenW32/S-e83a6442!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/MailRu.R potentially unwanted
ClamAVWin.Malware.Mailru-6804211-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderApplication.Agent.BOI
ViRobotTrojan.Win32.Agent.158352
AvastFileRepMetagen [PUP]
TencentTrojan.Win32.Reflo.ya
Ad-AwareApplication.Agent.BOI
EmsisoftApplication.AdMail (A)
ComodoApplication.Win32.MailRu.EC@6mwxfg
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
SophosMail.ru Downloader (PUA)
IkarusPUA.MailRu
GDataWin32.Application.MailRu.A
JiangminAdWare.Machaer.bm
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.A8F1
ArcabitApplication.Agent.BOI
SUPERAntiSpywarePUP.MailRU/Variant
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.MailRu.X2108
VBA32Adware.Downware
ALYacApplication.Agent.BOI
MAXmalware (ai score=74)
MalwarebytesPUP.Optional.RussAd
RisingPUF.MailRu!1.A9B5 (CLASSIC)
YandexRiskware.Agent!l+wV+lSL8Kg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/MailRu.M!tr
AVGFileRepMetagen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA.AgentPMF.S24894518?

PUA.AgentPMF.S24894518 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment