PUA

PUA:Win32/FusionCore.C removal guide

Malware Removal

The PUA:Win32/FusionCore.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/FusionCore.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/FusionCore.C?


File Info:

name: D74C472A4616E738E956.mlw
path: /opt/CAPEv2/storage/binaries/0d873e75caabd138fccf18b9a2c08f156a7c4f8c7c44b535db04b43487a615e8
crc32: 76D9A45C
md5: d74c472a4616e738e956e6cbec36f23b
sha1: c3729c7386b2570f49da416c9d33a82c32ba68fb
sha256: 0d873e75caabd138fccf18b9a2c08f156a7c4f8c7c44b535db04b43487a615e8
sha512: d7450271e42fa65680779e066b951f285358d68a2191c76d5cfa9b538331eaec5fb4d0b10214a1aaf620828a1fc545c8f3d75d3c0aac853a9f9379b65fc1255d
ssdeep: 196608:dN0X3/tm7jTmcs3wvM90tYGqx7QEb23KUww4Ij/tOj/jHFkNICFPPc010lhG:qo2csaJtSQs2aW/Ejb8NPHihG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4C6233FA267663EC56B0A3945729250597BBA60B81A4C1A0FF3185CCFE74701E3BE1D
sha3_384: dc754d793b6289256ce0d5df87ebb06810d38f6bbcc20363e42fcc4d0a46dc7b9a65d13a70061738f94edcaa13b60b12
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: PDFSpin Co., Ltd.
FileDescription: Free PDF Split Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Free PDF Split
ProductVersion:
Translation: 0x0000 0x04b0

PUA:Win32/FusionCore.C also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.Bundler.Relevant.A.8EAFFDF7
FireEyeGeneric.Application.Bundler.Relevant.A.8EAFFDF7
SkyhighArtemis
McAfeeArtemis!D74C472A4616
Cylanceunsafe
SangforAdware.Win32.Relevant.Vsq0
CrowdStrikewin/grayware_confidence_100% (W)
BitDefenderGeneric.Application.Bundler.Relevant.A.8EAFFDF7
ESET-NOD32multiple detections
AlibabaAdWare:Win32/FusionCore.05ea3985
AvastWin32:Adware-gen [Adw]
DrWebAdware.Relevant.189
SophosGeneric Reputation PUA (PUA)
Antiy-AVLGrayWare/Win32.Presenoker
ArcabitGeneric.Application.Bundler.Relevant.A.8EAFFDF7 [many]
MicrosoftPUA:Win32/FusionCore.C
VBA32Adware.Relevant
ALYacGeneric.Application.Bundler.Relevant.A.8EAFFDF7
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingAdware.RelevantKnowledge/IFPS!1.EDA7 (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/FusionCore
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove PUA:Win32/FusionCore.C?

PUA:Win32/FusionCore.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment