PUA

PUA.AgentRI.S18710387 removal guide

Malware Removal

The PUA.AgentRI.S18710387 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentRI.S18710387 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

live.windowchannel.bid
gool.eventhammer.bid

How to determine PUA.AgentRI.S18710387?


File Info:

crc32: 1A65B57E
md5: 9b987cbb4a9fb5a9d53bd47063f891ca
name: 9B987CBB4A9FB5A9D53BD47063F891CA.mlw
sha1: 1c31899d24bd8493f90dea7a5203641c2c06c74d
sha256: 237f69fc9eddc68601dfcaa030c6b4da6bac0d443018470f4c583cc771e71c1b
sha512: 5697daaf6ac747cf3ba86090d84a7a92d3bbc91707293b8ab7eed29614932d7102f2361faeab9057a5b0c8f16d6c9c6797fe911169b0af9faab087a270ecdf0d
ssdeep: 12288:siu9zpTvf1gtMVVhAFEv4ozlnjPeKnDBnLGAk6A9ZbzKZ:siYzpzfWgVhAWQcjrtLGAyKZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
ProductVersion: 1.0.0.1
FileVersion: 1.0.0.1
ProductName: TODO:
Translation: 0x0419 0x04b0

PUA.AgentRI.S18710387 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00528e801 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.13656
CynetMalicious (score: 100)
CAT-QuickHealPUA.AgentRI.S18710387
ALYacApplication.Bundler.ARW
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005103801 )
Cybereasonmalicious.b4a9fb
CyrenW32/StartSurf.AU.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.FWQG
APEXMalicious
AvastFileRepMetagen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderApplication.Bundler.ARW
NANO-AntivirusRiskware.Win32.StartSurf.ewuwad
MicroWorld-eScanApplication.Bundler.ARW
TencentMalware.Win32.Gencirc.10b3e473
Ad-AwareApplication.Bundler.ARW
SophosGeneric PUA BM (PUA)
ComodoApplication.Win32.IStartSurf.BS@7lng48
BitDefenderThetaGen:NN.ZexaF.34294.Ou0@aWWgvOdk
VIPREAdware.Win32.Wajam.ic (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.9b987cbb4a9fb5a9
EmsisoftApplication.Bundler.ARW (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.ajj
AviraHEUR/AGEN.1103354
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.23F479D
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataApplication.Bundler.ARW
AhnLab-V3PUP/Win32.StartSurf.C2283374
Acronissuspicious
McAfeePUP-XDL-SM
MAXmalware (ai score=72)
VBA32BScope.AdWare.StartSurf
MalwarebytesAdware.IStartSurf
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AF11 (CLASSIC)
YandexTrojan.GenAsa!2eAetAaOf+Y
IkarusTrojan.Agent
FortinetW32/Kryptik.FTMV!tr
AVGFileRepMetagen [Adw]
Paloaltogeneric.ml

How to remove PUA.AgentRI.S18710387?

PUA.AgentRI.S18710387 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment