PUA

What is “PUA.Installers1.Gen”?

Malware Removal

The PUA.Installers1.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.Installers1.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Anomalous binary characteristics

How to determine PUA.Installers1.Gen?


File Info:

name: 5F3C6A4DD5E87812F836.mlw
path: /opt/CAPEv2/storage/binaries/79492ce3b7aec9f3e1c00b5c940da312aebc0ec46d1652989ca302945f73e3e2
crc32: D16BDED5
md5: 5f3c6a4dd5e87812f8367fba4bdf17e9
sha1: 348cc54021886628191dbc2f6d84629a091d0fe1
sha256: 79492ce3b7aec9f3e1c00b5c940da312aebc0ec46d1652989ca302945f73e3e2
sha512: 12d44eb399b14e1b3d45c6992cab6944eab67883d5d9590709e588c499a77f76f54d276093a7023dece0c4e76af5abea02ad6b414aa199b6754daceebb00db32
ssdeep: 24576:CSFxIslMHC9uQBImEcFtQOsZB2JDYovvEncP8LMY+0qaO:rHYQW12pJDTb8NO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F2512507B6ADCA7D0350F3E4426F736896D7DBACD78914B34C1BA9F2823009C975A2B
sha3_384: 7bde89250335da1e9b7aacae43b7d66d66247a6dc1aece4b47309803858c61d991f463c142d589e436fcc06f8b251037
ep_bytes: 558bec83ec105356576a00ff15081049
timestamp: 2015-04-25 16:32:58

Version Info:

FileDescription: SweetPlayer
FileVersion: 3.0.0.95
InternalName: setup.exe
LegalCopyright: (c) Installer Setup
OriginalFilename: setup.exe
ProductName: SweetPlayer
ProductVersion: 3.0.0.95
CompanyName: Installer Setup
Translation: 0x0409 0x04b0

PUA.Installers1.Gen also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Bundler.DownloadAssistant.17
FireEyeGeneric.mg.5f3c6a4dd5e87812
CAT-QuickHealPUA.Installers1.Gen
McAfeeGenericRXCK-FK!5F3C6A4DD5E8
CylanceUnsafe
ZillyaTrojan.DownloadAssistGen.Win32.1
K7AntiVirusUnwanted-Program ( 004c44db1 )
K7GWUnwanted-Program ( 004c44db1 )
CrowdStrikewin/grayware_confidence_100% (D)
SymantecDownloader
ESET-NOD32a variant of Win32/DownloadAssistant.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Downloader-190
KasperskyUDS:Trojan.Win32.Bingoml
BitDefenderGen:Variant.Application.Bundler.DownloadAssistant.17
NANO-AntivirusTrojan.Win32.Vittalia.dwewuu
SUPERAntiSpywarePUP.DownloadAdmin/Variant
Ad-AwareGen:Variant.Application.Bundler.DownloadAssistant.17
EmsisoftGen:Variant.Application.Bundler.DownloadAssistant.17 (B)
ComodoApplication.Win32.DownloadAssistant.S@5msx5i
DrWebTrojan.Vittalia.194
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosDownload Assistant (PUA)
JiangminDownloader.DownloadAsist.b
AviraTR/Dropper.Gen
MAXmalware (ai score=72)
Antiy-AVLTrojan/Generic.ASBOL.34F2
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Application.DownloadAssistant.K
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Bundler.R145764
Acronissuspicious
ALYacGen:Variant.Application.Bundler.DownloadAssistant.17
VBA32BScope.Downloader.DownloadAsist
MalwarebytesPUP.Optional.DownloadAssistant
RisingAdware.DownloadAssistant!1.A3BC (CLASSIC)
YandexTrojan.GenAsa!2WJYNv6rGDw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.dd5e87
PandaTrj/Genetic.gen

How to remove PUA.Installers1.Gen?

PUA.Installers1.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment