PUA

PUA.MauvaiseRI.S5251627 (file analysis)

Malware Removal

The PUA.MauvaiseRI.S5251627 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.MauvaiseRI.S5251627 virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUA.MauvaiseRI.S5251627?


File Info:

crc32: F1468B95
md5: 60f518d66aa3e8256db5e219d6467b53
name: 60F518D66AA3E8256DB5E219D6467B53.mlw
sha1: d981f56facd23617fde909a20ba48bcdfed4ec35
sha256: 1dafc1eef748f142cc114b7828249ada277a2344615969d42083ba59bb05f1ac
sha512: 34be0b4c90710b863c02105c6ffee4e9e0cb487017f86a169d7a43b61fb642b041e6107a61bdf996c3b02f82771c1a461add825d2bbfd55a3ccddb0971442b96
ssdeep: 6144:0r2R6xzYE/rjH9NGmYrXPiqEMkGF5gQYgY:e9dAnXPi9KtxY
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Orange lime. All rights reserved.
InternalName: Tools manager
FileVersion: 2.3.1.4
CompanyName: Orange lime
Comments: App manager
ProductName: Istall tools manager
ProductVersion: 2.3.1.4
Translation: 0x0409 0x04b0

PUA.MauvaiseRI.S5251627 also known as:

K7AntiVirusUnwanted-Program ( 00587b2b1 )
DrWebTrojan.InstallMonster.2368
CynetMalicious (score: 100)
CAT-QuickHealPUA.MauvaiseRI.S5251627
ALYacGen:Variant.Jatif.722
CylanceUnsafe
ZillyaAdware.DLBoost.Win32.3335
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDownloader:Win32/Tovkater.b8d2982e
K7GWUnwanted-Program ( 00587b2b1 )
Cybereasonmalicious.66aa3e
CyrenW32/Tovkater.U.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/TrojanDownloader.Tovkater.EL
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tovkater-6646735-0
KasperskyTrojan-Downloader.Win32.Tovkater.e
BitDefenderGen:Variant.Jatif.722
NANO-AntivirusTrojan.Win32.InstallMonster.etfxom
MicroWorld-eScanGen:Variant.Jatif.722
TencentWin32.Trojan-downloader.Tovkater.Wpjp
Ad-AwareGen:Variant.Jatif.722
SophosMal/Generic-S
Comodofls.noname@0
BitDefenderThetaGen:NN.ZexaF.34266.hy0@amNGEYhi
VIPREAmonetize (fs)
TrendMicroTROJ_GEN.R002C0PJG21
McAfee-GW-EditionGenericR-KNQ!822556EFCCF3
FireEyeGeneric.mg.60f518d66aa3e825
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Tovkater.ai
AviraHEUR/AGEN.1108483
Antiy-AVLTrojan/Generic.ASMalwS.222D42C
MicrosoftSoftwareBundler:Win32/DirectDownloader
GDataGen:Variant.Jatif.722
AhnLab-V3PUP/Win32.DLBoost.R210363
McAfeeArtemis!60F518D66AA3
MAXmalware (ai score=99)
VBA32Trojan.Wacatac
MalwarebytesPUP.Optional.BundleInstaller
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PJG21
RisingTrojan.Generic@ML.99 (RDML:cU05s+kMUh0Mv6lH1MS/dA)
YandexTrojan.GenAsa!fhsyPjJLJo8
FortinetW32/Tovkater.EN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PUA.MauvaiseRI.S5251627?

PUA.MauvaiseRI.S5251627 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment