PUA

PUA.MauvaiseRI.S5254972 malicious file

Malware Removal

The PUA.MauvaiseRI.S5254972 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.MauvaiseRI.S5254972 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine PUA.MauvaiseRI.S5254972?


File Info:

name: 82741C8C6327492884FB.mlw
path: /opt/CAPEv2/storage/binaries/13f9c62234ea93934e8b997f30a547a3f895b23481ff8866b479ad7047bd4653
crc32: 97B13C8D
md5: 82741c8c6327492884fb8174480d15d7
sha1: e3668be89e6cb3036cc6de1d320a707c6fc72d58
sha256: 13f9c62234ea93934e8b997f30a547a3f895b23481ff8866b479ad7047bd4653
sha512: c801d7797944676e59d63c3c94d18095c2f39a46e9d2fc0163fd6607f60a6ec2ababcdc7db4028bbda667ab989e7321bd7105a9e05f5ef41f1027e9cf4a2fe30
ssdeep: 768:pFfZBBoaUZ+/zWnwe7kTF9tZtkc3rilAxuFUBLOUF:fFoNZbwe7iF9tDl3c3qBS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166F27C78B2C7CAB9ED12193937C5CBC5660A55A4F48C12D37F9803FE3FAA711461E168
sha3_384: 9f858dc6629d9737d081da49b372f38e7bb59cc2b9c62e588c855cfc253eaa0a8cf809e85853141c167a7dc6d2cf4fa5
ep_bytes: b8e81c41005064ff3500000000648925
timestamp: 2005-10-31 03:48:19

Version Info:

0: [No Data]

PUA.MauvaiseRI.S5254972 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.82741c8c63274928
CAT-QuickHealPUA.MauvaiseRI.S5254972
CylanceUnsafe
K7GWUnwanted-Program ( 004d38111 )
K7AntiVirusUnwanted-Program ( 004d38111 )
CyrenW32/Risk.WSOZ-7366
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Keygen.QN potentially unsafe
APEXMalicious
ClamAVWin.Trojan.Agent-885984
SUPERAntiSpywareTrojan.Agent/Gen-Banker
AvastWin32:Malware-gen
SophosKeygen (PUA)
ComodoMalware@#2ojqtsn662qle
VIPRETrojan.Win32.Generic!BT
TrendMicroCRCK_HISOC
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2413A4D
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Occamy.C13
CynetMalicious (score: 100)
McAfeeGeneric.djt
TrendMicro-HouseCallCRCK_HISOC
YandexTrojan.GenAsa!/1+GttO1PAk
IkarusTrojan-Downloader.Win32.Adload
FortinetW32/KeyGen.M!tr
AVGWin32:Malware-gen
Cybereasonmalicious.89e6cb
MaxSecureTrojan.Malware.1284855.susgen

How to remove PUA.MauvaiseRI.S5254972?

PUA.MauvaiseRI.S5254972 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment