PUA

About “PUA.AgentRI.S24813025” infection

Malware Removal

The PUA.AgentRI.S24813025 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentRI.S24813025 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine PUA.AgentRI.S24813025?


File Info:

name: B161D9895ABD6E06C338.mlw
path: /opt/CAPEv2/storage/binaries/58a484e35c6d339801d90376b7b1e3df27ad8ad0a0fcee46185271b07ec3cbaa
crc32: 66B9F786
md5: b161d9895abd6e06c338fa38733b2e45
sha1: 91f078cef24caaf7498aaff5517d4da6d277189c
sha256: 58a484e35c6d339801d90376b7b1e3df27ad8ad0a0fcee46185271b07ec3cbaa
sha512: e8791fb93c2143ce9dd1622b61608d5653bf97d49c9ab0661a9dc4891c777e27d941d2a366d63c92a61ba6942316b7e487a96b18035e4966da75852cd5588316
ssdeep: 24576:l3rskPbNxm0TDWvknxNcKi2Mc/DDC8XlLmtYm+PPW6JQoSws+Opv5sh3y4aJM8dK:NPhxm0PWvt8oUWkQTneKoDcTTfjZospQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B65BF21B841C032E66201F1857DAB698ABCBE30076594D7E3D87E689F705D2BB3771B
sha3_384: cfc13510b3ab62706b98390b164fc9b967bf1c0a2f8b07d21e2b576b50da2ad1beed776154d9738714d417da27d570b2
ep_bytes: e82d080000e98efeffff8b4df464890d
timestamp: 2021-04-19 07:09:37

Version Info:

CompanyName: 上海展盟网络科技有限公司
FileDescription: upgrade.exe
FileVersion: 3.3.0.2
InternalName: upgrade.exe
LegalCopyright: Copyright © 2019 上海展盟网络科技有限公司 All Rights Reserved
OriginalFilename: upgrade.exe
ProductName: upgrade.exe
ProductVersion: 3.3.0.2
Translation: 0x0804 0x04b0

PUA.AgentRI.S24813025 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.KuziTui.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.80351
FireEyeGeneric.mg.b161d9895abd6e06
CAT-QuickHealPUA.AgentRI.S24813025
McAfeeGenericRXQV-BD!B161D9895ABD
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.bh
K7AntiVirusAdware ( 00565ab71 )
AlibabaAdWare:Win32/KuaiZip.5976cadf
K7GWAdware ( 00565ab71 )
Cybereasonmalicious.ef24ca
ArcabitTrojan.Generic.D139DF
BitDefenderThetaGen:NN.ZexaF.34062.yD2@aGy@AFlj
CyrenW32/KuaiZip.T.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KuaiZip.AB potentially unwanted
TrendMicro-HouseCallPE_SALITY.ER
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
BitDefenderTrojan.GenericKDZ.80351
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
TencentPua:Adware.Win32.Kuzitui.16000040
Ad-AwareTrojan.GenericKDZ.80351
SophosGeneric PUA JB (PUA)
DrWebTrojan.Siggen15.13229
VIPREVirus.Win32.Sality.atbh (v)
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKDZ.80351 (B)
APEXMalicious
JiangminAdWare.KuziTui.abo
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Generic
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotAdware.Kuzitui.1448328.I
GDataTrojan.GenericKDZ.80351
Acronissuspicious
VBA32BScope.Adware.Burden
ALYacTrojan.GenericKDZ.80351
MAXmalware (ai score=82)
MalwarebytesPUP.Optional.Kuaizip
RisingAdware.Agent!1.C6CF (CLASSIC)
IkarusTrojan.Win32
eGambitUnsafe.AI_Score_71%
FortinetAdware/KuaiZip.AB
AVGWin32:Sality [Inf]
AvastWin32:Sality [Inf]

How to remove PUA.AgentRI.S24813025?

PUA.AgentRI.S24813025 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment