PUA

About “PUABundler:Win32/FusionCore” infection

Malware Removal

The PUABundler:Win32/FusionCore is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUABundler:Win32/FusionCore virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine PUABundler:Win32/FusionCore?


File Info:

name: D144C012E0BC8BFA4866.mlw
path: /opt/CAPEv2/storage/binaries/0f6776fa8e59617c52a5b3b3b816c43f85bc94cd8b0b115a3ce0ae0e3c0b99a6
crc32: 10155516
md5: d144c012e0bc8bfa4866ccd226d9f74a
sha1: 62d37697e353a48570571552dae23ec62077f54a
sha256: 0f6776fa8e59617c52a5b3b3b816c43f85bc94cd8b0b115a3ce0ae0e3c0b99a6
sha512: b497b39c579b32b09dbe5c9bdbf2b00ff62f3484fa788426a23064ee3b9287247c0111cd31ffd9eea830d1018cde1862c338dda7c7e8d8f72bd0f2629e142e88
ssdeep: 98304:TUoVk2EZhnEb7gBBesi/tRjsQjMoDSNIZXOpeZZleOUxNU0xzehnpbV0o4ryk5El:W2tb7gnHi7jhgQ7OkzleOUxmQAt4OVl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C56633AEB1DA4276CD4C157209E7EDBD933B90F96E0003D67A44CB65E17938A8F2B740
sha3_384: 98e5ad283d2fa82f4ec521defb01b61ed1671a41111ef54f0df39317200bb338e4f3f24d8b9e7e70fa4ab82a98ba66a3
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-12-11 21:50:45

Version Info:

0: [No Data]

PUABundler:Win32/FusionCore also known as:

LionicTrojan.MSIL.DOTHETUK.4!c
DrWebTrojan.InstallCore.2673
MicroWorld-eScanTrojan.GenericKD.37696063
FireEyeTrojan.GenericKD.37696063
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.41401485
CylanceUnsafe
SangforTrojan.MSIL.DOTHETUK.ewz
K7AntiVirusTrojan ( 00575cff1 )
AlibabaAdWare:Win32/FusionCore.9a82167e
K7GWTrojan ( 00575cff1 )
Cybereasonmalicious.2e0bc8
CyrenW32/FusionCore.A.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R031C0PDQ21
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9853542-0
KasperskyTrojan.MSIL.DOTHETUK.ewz
BitDefenderTrojan.GenericKD.37696063
NANO-AntivirusRiskware.Win32.Mlw.eftqvz
AvastFileRepMetagen [PUP]
TencentTrojan.Win32.BitCoinMiner.la
EmsisoftTrojan.GenericKD.37696063 (B)
ComodoMalware@#c8skrg8l17bz
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R031C0PDQ21
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
SophosGeneric PUA GC (PUA)
GDataWin32.Application.FusionCore.D
eGambitUnsafe.AI_Score_71%
AviraHEUR/AGEN.1129312
Antiy-AVLTrojan/Generic.ASMalwS.253B25
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D23F323F
MicrosoftPUABundler:Win32/FusionCore
CynetMalicious (score: 99)
McAfeeArtemis!D144C012E0BC
MAXmalware (ai score=80)
VBA32Downloader.Funshion
APEXMalicious
YandexRiskware.Agent!wCXR3ZXxPF0
FortinetW32/DOTHETUK.EWZ!tr
WebrootW32.Trojan.GenKD
AVGFileRepMetagen [PUP]
PandaTrj/CI.A

How to remove PUABundler:Win32/FusionCore?

PUABundler:Win32/FusionCore removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment