PUA

PUA.MailRu.S124773 removal instruction

Malware Removal

The PUA.MailRu.S124773 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.MailRu.S124773 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine PUA.MailRu.S124773?


File Info:

name: F4CAD706C8DF3321D67D.mlw
path: /opt/CAPEv2/storage/binaries/931b63c8cb63eb0db4bdbbcaf227f920b70f581389fba51c4ce8f67712365dff
crc32: 7DA9E2F0
md5: f4cad706c8df3321d67d65e2f1b8dc6a
sha1: 144be5a34ecd76cbea3df2ceef20975cf5ae4cb6
sha256: 931b63c8cb63eb0db4bdbbcaf227f920b70f581389fba51c4ce8f67712365dff
sha512: ee5286df340e6bafc9de5b15dc9b6162bbefe2837b2561737b19654eb0756c5fbd8736993ced36affca5650741840985625f53d684079699c51babd23cb38079
ssdeep: 6144:lrZxAPgGCtlTE6p6aFXFUedSqR3Lc3AOTgQDBxHfoE13+:lQetlTE6p6QXOeJE2QLQ63+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190848B01758DC43EC57256320935E6A1A978BD300E30F65F63E87F2DFFB1181A629AA7
sha3_384: cb1c39f0fa75e0b820b9d033eb7aff8bab2654ac8d9d19ef35dc2c9dd12acf64676700ba1b580f3ae0dc393f9ff3e50c
ep_bytes: e800060000e98efeffffff25d0f34200
timestamp: 2016-12-01 15:55:47

Version Info:

CompanyName: Mail.Ru
FileDescription: Amigo@Mail.Ru
FileVersion: 2.0.0.169
InternalName: Amigo Mail.Ru
LegalCopyright: Copyright 2015
OriginalFilename: Amigo@Mail.Ru
ProductName: Amigo@Mail.Ru
ProductVersion: 2.0.0.169
Translation: 0x0409 0x04b0

PUA.MailRu.S124773 also known as:

LionicRiskware.Win32.Generic.1!c
CAT-QuickHealPUA.MailRu.S124773
McAfeeGenericRXAA-FA!F4CAD706C8DF
CylanceUnsafe
SangforTrojan.Win32.BSE.OW4OJ9
K7AntiVirusUnwanted-Program ( 00586df41 )
K7GWUnwanted-Program ( 00586df41 )
CyrenW32/S-506e523c!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/MailRu.B potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OKS21
SUPERAntiSpywarePUP.MailRU/Variant
AvastFileRepMetagen [PUP]
ComodoApplication.Win32.MailRu.BACS@6kp8ua
ZillyaTrojan.Hematite.Win32.96
TrendMicroTROJ_GEN.R002C0OKS21
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA BE (PUA)
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotAdware.Mailru.401640.EB
GDataWin32.Trojan.BSE.OW4OJ9
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.3BBEB9!tr
AVGFileRepMetagen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA.MailRu.S124773?

PUA.MailRu.S124773 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment