PUA

PUA.MauvaiseRI.S5256147 information

Malware Removal

The PUA.MauvaiseRI.S5256147 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.MauvaiseRI.S5256147 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Authenticode signature is invalid

How to determine PUA.MauvaiseRI.S5256147?


File Info:

name: 722ABC647FB1A83A86ED.mlw
path: /opt/CAPEv2/storage/binaries/3a0b0185975bc85c85265c7acc07a13540e72216f1e6e95b7eadb74f591f8a71
crc32: 5121FA3C
md5: 722abc647fb1a83a86edea002edc12a2
sha1: 2628cf06113a5dbfd400875d772f088526e30d46
sha256: 3a0b0185975bc85c85265c7acc07a13540e72216f1e6e95b7eadb74f591f8a71
sha512: f130e18a6310168b054c9583959cdba88c580a6fa214519cc51281dabd7f1662304df8fd09fe161c420f3656fc3efd0cc35a0aa6a4ee6178e82e95a3b9b92e9c
ssdeep: 24576:ntZbRs3bb7wQ0aMZp4hoQbjG7xX0R4nPbB6UWTnquU/9vMDLZqC5i6GB:ntZbM/f4EA5W3ZqC59Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112555C02A7839062E25601B531D47A76A87830781B1AA4D7F7476F143CAA3E2E7FCF57
sha3_384: 8ab04082ddccb8d14cf8686b2b2ab6e205a634fa0cf1634022b29ae452882691853189866fc0686bef5a0ce65c62ac24
ep_bytes: e85f1b0100e97ffeffff558bec568b75
timestamp: 2021-12-03 16:29:27

Version Info:

FileVersion: 1.0.8007.15209
ProductVersion: 1.0.8007.15209
Translation: 0x0409 0x04b0

PUA.MauvaiseRI.S5256147 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.BrowseFox.321
CAT-QuickHealPUA.MauvaiseRI.S5256147
ALYacGen:Variant.Adware.BrowseFox.321
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 005203a21 )
K7GWUnwanted-Program ( 005203a21 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34084.vv0@auPJvdhi
CyrenW32/S-d4ca5e63!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.BrowseFox.AU
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Adware.BrowseFox.321
SUPERAntiSpywarePUP.Yontoo/Variant
AvastWin32:Evo-gen [Susp]
RisingAdware.BrowseFox!1.A470 (CLASSIC)
Ad-AwareGen:Variant.Adware.BrowseFox.321
SophosGeneric ML PUA (PUA)
F-SecureAdware.ADWARE/BrowseFox.Gen
McAfee-GW-EditionBehavesLike.Win32.BrowseFox.th
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.722abc647fb1a83a
EmsisoftGen:Variant.Adware.BrowseFox.321 (B)
IkarusBHO.Win32.Foxiebro
GDataGen:Variant.Adware.BrowseFox.321
JiangminAdWare.Generic.kudv
AviraADWARE/BrowseFox.Gen
ArcabitTrojan.Adware.BrowseFox.321
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BrowseFox.C2260289
Acronissuspicious
McAfeeBrowseFox-FAU
VBA32BScope.Adware.BrowseFox
MalwarebytesAdware.Yontoo
APEXMalicious
TencentAdware.Win32.Browsefox.c
YandexTrojan.GenAsa!wYz7cuzoEow
MAXmalware (ai score=60)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/BrowseFox
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.47fb1a
PandaTrj/GdSda.A

How to remove PUA.MauvaiseRI.S5256147?

PUA.MauvaiseRI.S5256147 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment