PUA

PUA.Worldsetup.Gen removal tips

Malware Removal

The PUA.Worldsetup.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.Worldsetup.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine PUA.Worldsetup.Gen?


File Info:

name: AE4F3FE229A7E3CA3955.mlw
path: /opt/CAPEv2/storage/binaries/5bcc273ba4e0c02dcb86c481d53e8059af8ee8e81b224beb3c6cb8aaea3a2ecd
crc32: 765137B5
md5: ae4f3fe229a7e3ca3955eb0abe879a58
sha1: 0b97305bac48c9b73e3c351efaa32b64964dc0da
sha256: 5bcc273ba4e0c02dcb86c481d53e8059af8ee8e81b224beb3c6cb8aaea3a2ecd
sha512: d4239c7f0b26462c7807d592ab9930c5a2fdaf7bbd7d8779678dd1dbe5382adccb6ce83236ae3a5908b79e4982e1cca9a0da3d1bd64cbbdd208aeb63596615f2
ssdeep: 12288:uvp8lJO8VAvmRwtSTwL0Ja1RfgYWjrmcT0rNmcgIxnVgWFkATozhn:uvwO8RRwt85QTsUNm1IxV7FIhn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAE423D77D9AC8B8F2E8C17789E18101A6273E483F34241271BCFA49AF3B1D5690E365
sha3_384: 541dde4877f09aced7a79648ceb810edef35f42386d5925617e061c1579f318a39b0451540f891b94ddcab1d9e1be3db
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
Translation: 0x0000 0x04b0

PUA.Worldsetup.Gen also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Malware.Installcore-6931976-0
FireEyeGeneric.mg.ae4f3fe229a7e3ca
CAT-QuickHealPUA.Worldsetup.Gen
McAfeeArtemis!AE4F3FE229A7
CylanceUnsafe
ZillyaTrojan.InstallCoreCRTD.Win32.1043
K7AntiVirusAdware ( 004df3d61 )
K7GWAdware ( 004df3d61 )
VirITPUP.Win32.WorldSetup.A
CyrenW32/A-d2b7439f!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
BaiduWin32.Adware.InstallCore.a
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
NANO-AntivirusRiskware.Win32.InstallCore.dcnbfi
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
SophosInstall Core (PUA)
ComodoApplication.Win32.Installcore.BB@57pye1
DrWebTrojan.Packed.24524
McAfee-GW-EditionArtemis!PUP
Trapminemalicious.high.ml.score
EmsisoftApplication.InstallCore (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.InstallCore.J
WebrootPua.Wajam.Bho
AviraPUA/InstallCore.Gen
Antiy-AVLTrojan/Generic.ASMalwS.330C
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.DealPly.gen
MicrosoftPUADlManager:Win32/InstallCore
GoogleDetected
AhnLab-V3PUP/Win32.InstallCore.R338349
Acronissuspicious
VBA32Downware.InstallCore
MalwarebytesPUP.Optional.InstallCore
RisingTrojan.Generic@AI.100 (RDMK:+Wt3sVbfZxMC6ayVEySa1A)
YandexTrojan.Injected!VDlPcEv8s8Q
IkarusTrojan-Spy.Zbot
MaxSecureAdware.DealPly.gen14_171748
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUA.Worldsetup.Gen?

PUA.Worldsetup.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment