Malware

Should I remove “UDS:AdWare.Win32.Machaer”?

Malware Removal

The UDS:AdWare.Win32.Machaer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:AdWare.Win32.Machaer virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine UDS:AdWare.Win32.Machaer?


File Info:

name: 142E84031E75DF550108.mlw
path: /opt/CAPEv2/storage/binaries/124f7f48b0cfdc617f60347d495d371c9672207938a42ea29e451fd1eee0122e
crc32: 8925515B
md5: 142e84031e75df55010828f5163f8713
sha1: 950546e42742563f46d12a2b378fdaa237148f83
sha256: 124f7f48b0cfdc617f60347d495d371c9672207938a42ea29e451fd1eee0122e
sha512: e7e5e24ae0f7239b1388abcde6b33a2612008e54e169029ba7557aab63ceee0f25c9850296f7134e43e006e7c402859178e6821ba9b2d16afdfef685cdcaae9b
ssdeep: 3072:sLp+mpINRBwCUDfeh+DAxxWQuWkhQOuvg:s9LpivMzehw5Grv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13EE38C1237D0C071F5B6023249B5AB65593EFD724BB485DBB398471E19B07C0AB3ABA3
sha3_384: 854489ee6152f857ab93134f3167b077b9794652017d6d5c5d1c1c76f33a1f57bf09925e09f479739da7754681ed0c88
ep_bytes: e8bc5a0000e97ffeffffcccccc8b4c24
timestamp: 2016-07-07 12:30:08

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.6.0.6
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.6.0.6
Comments:
Translation: 0x0409 0x04b0

UDS:AdWare.Win32.Machaer also known as:

DrWebAdware.StartPage.42
MicroWorld-eScanGen:Variant.Application.Agent.6
FireEyeGeneric.mg.142e84031e75df55
ALYacGen:Variant.Application.Agent.6
MalwarebytesMalware.AI.2458846082
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00587ee01 )
K7GWUnwanted-Program ( 00587ee01 )
Cybereasonmalicious.31e75d
CyrenW32/S-e83a6442!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/MailRu.J potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PL721
CynetMalicious (score: 100)
Kasperskynot-a-virus:UDS:AdWare.Win32.Machaer
BitDefenderGen:Variant.Application.Agent.6
NANO-AntivirusTrojan.Win32.MailRu.enfiqs
SUPERAntiSpywarePUP.MailRU/Variant
AvastWin32:PUP-gen [PUP]
Ad-AwareGen:Variant.Application.Agent.6
EmsisoftApplication.AdMail (A)
ComodoApplication.Win32.MailRu.BS@6ku3o6
TrendMicroTROJ_GEN.R002C0PL721
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
SophosMail.ru Downloader (PUA)
IkarusPUA.MailRu
JiangminTrojan.Reflo.a
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotAdware.Mailru.145552.CHH
GDataGen:Variant.Application.Agent.6
AhnLab-V3PUP/Win.MailRu.X2108
McAfeeGenericRXNI-OL!142E84031E75
MAXmalware (ai score=77)
VBA32Adware.StartPage
CylanceUnsafe
RisingPUF.MailRu!1.A9B5 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/MailRu.M!tr
AVGWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove UDS:AdWare.Win32.Machaer?

UDS:AdWare.Win32.Machaer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment