PUA

PUA.MailRu.S232696 removal tips

Malware Removal

The PUA.MailRu.S232696 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.MailRu.S232696 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine PUA.MailRu.S232696?


File Info:

name: 306B900ADF2337584487.mlw
path: /opt/CAPEv2/storage/binaries/cbc39e38a28982fe9f7ee4ca8aa09135f2f3419f16ad8743bff6cc7f10d6b860
crc32: 6357094D
md5: 306b900adf233758448787f28b43d59c
sha1: 4732ffb27b99310bfc01d8bf19fba48c0fbfa2b6
sha256: cbc39e38a28982fe9f7ee4ca8aa09135f2f3419f16ad8743bff6cc7f10d6b860
sha512: 7a110f05107ae2ab1e7f4bed9992f1c8d6c004bfdb9789d6390b71b8964ed7affcc16dfc96bbb6e601d69aa76595bb371b6a92212690878f8ae7dcc6dc73997f
ssdeep: 3072:DrAVguiZxHF02SOacgAf+9mzB7y7YRguXt:DWgVZ1vGAfL1X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180F37C0237C1C0B0EAE7023109B89B66597DFD714BB049D7B7984B1E6DB06D0AB36B67
sha3_384: 0e290d3610498623baf0cb0a91b2124d36b37ff75d6fcb56dc4e26626f4fb982c6c29767ac3d3f9c6e75f6ae0a91a7b0
ep_bytes: e8a6730000e97ffeffff558bec568b75
timestamp: 2016-09-23 08:27:17

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.9.0.1
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.9.0.1
Comments:
Translation: 0x0409 0x04b0

PUA.MailRu.S232696 also known as:

Elasticmalicious (high confidence)
DrWebAdware.Downware.17838
MicroWorld-eScanApplication.Agent.BOI
CAT-QuickHealPUA.MailRu.S232696
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 004fffcd1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.adf233
CyrenW32/S-e83a6442!Eldorado
ESET-NOD32a variant of Win32/MailRu.R potentially unwanted
ClamAVWin.Malware.Mailru-6804211-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderApplication.Agent.BOI
SUPERAntiSpywarePUP.MailRU/Variant
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareApplication.Agent.BOI
SophosMail.ru Downloader (PUA)
ComodoApplication.Win32.MailRu.EC@6mwxfg
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
FireEyeApplication.Agent.BOI
EmsisoftApplication.AdMail (A)
IkarusPUA.MailRu
GDataWin32.Application.MailRu.A
JiangminAdWare.Machaer.bm
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.A8F1
ArcabitApplication.Agent.BOI
ViRobotTrojan.Win32.Agent.158352
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.MailRu.X2108
VBA32Adware.Downware
ALYacApplication.Agent.BOI
MAXmalware (ai score=73)
MalwarebytesPUP.Optional.RussAd
RisingPUF.MailRu!1.A9B5 (CLASSIC)
YandexRiskware.Agent!l+wV+lSL8Kg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/MailRu.M!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA.MailRu.S232696?

PUA.MailRu.S232696 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment