Malware

What is “Win32/MailRu.J potentially unwanted”?

Malware Removal

The Win32/MailRu.J potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/MailRu.J potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Win32/MailRu.J potentially unwanted?


File Info:

name: 2D6DA09D3D64EA6F4C6F.mlw
path: /opt/CAPEv2/storage/binaries/c9aee9fac9a5e4d0c4c185e3d7b2ae205d4d74583642e17b6fdb6cfc5db960ed
crc32: 31E53266
md5: 2d6da09d3d64ea6f4c6f761c9fbc6e2c
sha1: 2168937ede3cb4a10fd4ec18f0aff08a82f9cfbf
sha256: c9aee9fac9a5e4d0c4c185e3d7b2ae205d4d74583642e17b6fdb6cfc5db960ed
sha512: 9fff0d79a3ca383240d572ae1017bc57035c123b370ab7597c83074930ecc170499bd7c7c6c4f43fbc7b9e71bd5b5fcceba439cec06507459745892a04a78478
ssdeep: 3072:sLp+mpINRBwCUDfeh+DAxxWQuWkhQOuvg:s9LpivMzehw5Grv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2E38C1237D0C071F5B6023259B49B61593EFD724BB489DBB398471E19B07C0AB3ABA3
sha3_384: ef2463729a8fcdd9a807bca728c6b182673d5304f99867529c7b8b5572410d227451f505fc7773f7da03101cb1110399
ep_bytes: e8bc5a0000e97ffeffffcccccc8b4c24
timestamp: 2016-07-07 12:30:08

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.6.0.6
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.6.0.6
Comments:
Translation: 0x0409 0x04b0

Win32/MailRu.J potentially unwanted also known as:

LionicRiskware.Win32.MailRu.1!c
MicroWorld-eScanGen:Variant.Application.Agent.6
FireEyeGeneric.mg.2d6da09d3d64ea6f
McAfeeGenericRXNI-OL!2D6DA09D3D64
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00587ee01 )
K7GWUnwanted-Program ( 00587ee01 )
Cybereasonmalicious.d3d64e
CyrenW32/S-e83a6442!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/MailRu.J potentially unwanted
Kasperskynot-a-virus:UDS:AdWare.Win32.Machaer
BitDefenderGen:Variant.Application.Agent.6
NANO-AntivirusTrojan.Win32.MailRu.enfiqs
SUPERAntiSpywarePUP.MailRU/Variant
AvastWin32:PUP-gen [PUP]
Ad-AwareGen:Variant.Application.Agent.6
EmsisoftApplication.AdMail (A)
ComodoApplication.Win32.MailRu.BS@6ku3o6
DrWebTrojan.Zadved.649
TrendMicroTROJ_GEN.R002C0PL621
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
SophosMail.ru Downloader (PUA)
IkarusPUA.MailRu
GDataGen:Variant.Application.Agent.6
JiangminTrojan.Reflo.a
MAXmalware (ai score=72)
ArcabitTrojan.Application.Agent.6
MicrosoftProgram:Win32/Uwamson.A!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.MailRu.X2108
VBA32Adware.StartPage
ALYacGen:Variant.Application.Agent.6
MalwarebytesMalware.AI.2458846082
TrendMicro-HouseCallTROJ_GEN.R002C0PL621
RisingPUF.MailRu!1.A9B5 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/MailRu.M!tr
AVGWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/MailRu.J potentially unwanted?

Win32/MailRu.J potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment