PUA

How to remove “PUA.MauvaiseRI.S5264012”?

Malware Removal

The PUA.MauvaiseRI.S5264012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.MauvaiseRI.S5264012 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUA.MauvaiseRI.S5264012?


File Info:

crc32: 9A95DE44
md5: 6b83c94f1ab619275f03dc0368e5de32
name: 6B83C94F1AB619275F03DC0368E5DE32.mlw
sha1: d954b0a45f3d6f2f43f83b11763970855cd0a2ac
sha256: 2494727a8cfd47858c5082d09f19084f3577a746af97c4cc5aa30c02c3742261
sha512: d4d9e66008fa7bb28a3762bd68a8d55b7c68b61a0b1c159204b430f8b17ba422ee14f342b881e5baac0c17e4869f8982457c7d7fc4f298968f787bbc6a12cbce
ssdeep: 24576:TUtKHhS8/izD64eVT6QJ25yFONQu9Cok7SB/jE0AvrbgAvIq5vcO4zt2:YUBpazD64kWBqik7SjATMAQ2vcO4zA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 10.2.1.2363
ProductName: ADCORE Internet Security
FileVersion: 10.2.1.2363
CompanyName: ADCORE
Translation: 0x0409 0x04e4

PUA.MauvaiseRI.S5264012 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00545ca21 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealPUA.MauvaiseRI.S5264012
ALYacGen:Variant.Zusy.356049
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.16579
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Katusha.19bf1223
K7GWTrojan ( 00545ca21 )
Cybereasonmalicious.f1ab61
CyrenW32/Icloader.CB.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GNHK
APEXMalicious
AvastWin32:ICLoader-X [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.356049
NANO-AntivirusTrojan.Win32.Ekstak.fkshwd
MicroWorld-eScanGen:Variant.Zusy.356049
TencentMalware.Win32.Gencirc.10cd3cec
Ad-AwareGen:Variant.Zusy.356049
SophosGeneric PUA NJ (PUA)
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34266.qA0@aS8KGVii
McAfee-GW-EditionBehavesLike.Win32.Worm.vh
FireEyeGeneric.mg.6b83c94f1ab61927
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.wid
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.29C4BFD
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitTrojan.Zusy.D56ED1
GDataGen:Variant.Zusy.356049
TACHYONTrojan/W32.Ekstak.2367488
AhnLab-V3PUP/Win32.ICLoader.R246964
Acronissuspicious
McAfeePacked-FME!6B83C94F1AB6
MAXmalware (ai score=82)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!kxp19Fprw0w
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove PUA.MauvaiseRI.S5264012?

PUA.MauvaiseRI.S5264012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment