PUA

Open Install (PUA) removal instruction

Malware Removal

The Open Install (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Open Install (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

st.cloins.com
inst.avg.com

How to determine Open Install (PUA)?


File Info:

crc32: 7872E544
md5: 8bf733ae48327c120940ba37629d41ab
name: 25296-669625-winzip.exe
sha1: 8499d3321b8c4f9cbb6ccff33553415fc6f894e4
sha256: 7a1551c86ac5fd32dfd0c5c2dacd6f71564f5b1cc9ce8bd2b815d3ddbee7c2fe
sha512: 9f80bf5246942ec95416710d5bb863eb628877e49d8960bfdc9e355e8ec616b09ae11db66cfd6e6658d46fc102fcffa10f1df8250d370c23f0f092e035e9dc9b
ssdeep: 6144:s3ctoLU3AfFKMxnG8PJf2BQV504y8KLBy2wtsWftySDNqsGTUb4j:s8QKknGcAk0/8KrXYtySDhGUb4j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012
FileVersion: 1,18,0,2949
CompanyName: WinZip Computing
ProductName: WinZip 17
ProductVersion: 1,18,0,2949
FileDescription: WinZip 17 Setup
Translation: 0x0000 0x0000

Open Install (PUA) also known as:

FireEyeGeneric.mg.8bf733ae48327c12
CAT-QuickHealTrojan.Generic
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_80% (D)
K7GWAdware ( 004a9bdf1 )
K7AntiVirusAdware ( 004a9bdf1 )
F-ProtW32/S-ca8455f6!Eldorado
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Openinstall-6879831-0
GDataWin32.Application.OpenInstall.D@gen
NANO-AntivirusRiskware.Win32.Adw.dszcbf
RisingTrojan.Bitrep!8.F596 (CLOUD)
SophosOpen Install (PUA)
ComodoApplication.Win32.OpenInstall.SAS@6v0z36
DrWebAdware.Downware.1348
ZillyaAdware.AlteredSoftware.Win32.67
Invinceaheuristic
Trapminemalicious.high.ml.score
CyrenW32/S-ca8455f6!Eldorado
WebrootPua.Open.Install
AviraPUA/OpenInstall.Gen
Antiy-AVLGrayWare[AdWare]/Win32.OpenInstall
Endgamemalicious (high confidence)
SUPERAntiSpywarePUP.OpenInstall/Variant
MicrosoftPUA:Win32/Vigua.A
CynetMalicious (score: 85)
VBA32BScope.Downloader.Agent
ESET-NOD32a variant of Win32/OpenInstall potentially unwanted
YandexRiskware.OpenInstall!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/OpenInstall

How to remove Open Install (PUA)?

Open Install (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment