PUA

What is “Install Core Installer (PUA)”?

Malware Removal

The Install Core Installer (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Install Core Installer (PUA) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Install Core Installer (PUA)?


File Info:

name: AB7854533F32D717FB90.mlw
path: /opt/CAPEv2/storage/binaries/bcd7ded6920d11a9a9b90e53fe697a2a92e96d867163e9a8d58fd67e7db9dcb2
crc32: 047B4BAD
md5: ab7854533f32d717fb90e778c43976f0
sha1: 733e674c087aa797e4e580f93402d774fb0a6edf
sha256: bcd7ded6920d11a9a9b90e53fe697a2a92e96d867163e9a8d58fd67e7db9dcb2
sha512: 440c4afe0faa10f1c8b172ce2a16be8f8b7be2909be18d3090a73f84c0c103b22d0bc8b5f5ee6a3765754a085a0e13cc56e08fee1e80efe5dcedf3a8a339b177
ssdeep: 12288:0EnvpPgfwvLYDZtzRgNoU+9qu9OToO6bXUk+t3Nbsd2T33v3ldbrT:0EnvtiwTYDZtzWoL9qmOsOn9Ad2T33v3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7E42352CFD5D07DE09225B04C2662285D76FF448C9B02103AEC7E5CBF7AA91C8793AE
sha3_384: 39d9b8b71f6f55af09a05442d8ee7b463c2af99ad48808542ebc41fad68bc1f9da59dac370a1925c6100e2be73bd304f
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Install Core Installer (PUA) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lXkC
FireEyeGeneric.mg.ab7854533f32d717
CAT-QuickHealTrojan.Dorv.B8
SkyhighArtemis!PUP
Cylanceunsafe
ZillyaTrojan.InstallCore.Win32.486
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/InstallCore.43e933d1
K7GWAdware ( 0055dcfb1 )
K7AntiVirusAdware ( 0055dcfb1 )
VirITPUP.Win32.UpdateStar.A
SymantecSMG.Heur!gen
ESET-NOD32Win32/InstallCore.Gen.D potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0OBN24
AvastFileRepMalware [Misc]
ClamAVWin.Trojan.Heur2-225
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
NANO-AntivirusRiskware.Win32.InstallCore.dfgopz
SUPERAntiSpywarePUP.InstallCore/Variant
RisingTrojan.Generic@AI.100 (RDMK:9a0wercRY/4Mpw3oW0eZLA)
SophosInstall Core Installer (PUA)
F-SecurePotentialRisk.PUA/InstallCore.Gen7
DrWebTrojan.MulDrop5.10078
TrendMicroTROJ_GEN.R002C0OBN24
Trapminemalicious.high.ml.score
MAXmalware (ai score=96)
WebrootPua.Update.Star
GoogleDetected
AviraPUA/InstallCore.Gen7
VaristW32/A-92167483!Eldorado
Antiy-AVLTrojan/Win32.SGeneric
Kingsoftmalware.kb.a.918
MicrosoftPUADlManager:Win32/InstallCore
XcitiumApplication.Win32.InstallCore.BWAN@58je91
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataWin32.Application.InstallCore.CZ
CynetMalicious (score: 100)
McAfeeArtemis!AB7854533F32
MalwarebytesPUP.Optional.InstallCore.DDS
PandaPUP/Multitoolbar
TencentMalware.Win32.Gencirc.10b13bba
YandexTrojan.MulDrop!44UWGU5nMHY
SentinelOneStatic AI – Malicious PE
MaxSecureAdware.not-a-virus.WIN32.AdWare.DealPly.gen_194606
FortinetRiskware/InstallCore
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove Install Core Installer (PUA)?

Install Core Installer (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment