PUA

How to remove “PUA:Win32/InstallMetrix”?

Malware Removal

The PUA:Win32/InstallMetrix is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/InstallMetrix virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/InstallMetrix?


File Info:

name: 4B7B09A69CA64C00AB87.mlw
path: /opt/CAPEv2/storage/binaries/bba0fcb10aeb1bf833b3431b4c3e00f79c706610f19a93cfc4185b018ce9690b
crc32: 6D90C2B3
md5: 4b7b09a69ca64c00ab878fd82038ba0e
sha1: 9220ba6d34be429d34be601683460786b1a23c38
sha256: bba0fcb10aeb1bf833b3431b4c3e00f79c706610f19a93cfc4185b018ce9690b
sha512: e39fb222837052a5065fa5eb899390467a1400424e516fdc81b3e1f88a1befe16884e268a0ef77ad4f5640f38f3bda69b5aa96a6a1d9988993985f83a472bb2b
ssdeep: 24576:M7kSLsPpRbwFnyOrd41zcDbuLvpVnwX4p:G1sR6FnyOrd4S6pVt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1662523C6BA40E876E9B509F095BAE53116FA3C50276712CF33D8317B99324D6071E3AB
sha3_384: 585a669dfb31ddeca52598c74c664e0c0085e27c29e2be2574c538eb8147aa392bc552cef867354f9f0377ce350c5c31
ep_bytes: e8501b0000e989feffff8bff558bec81
timestamp: 2014-10-24 20:27:09

Version Info:

CompanyName: TODO:
FileDescription: Chrome_Updater
FileVersion: 1.0.0.1
InternalName: Installer.exe
LegalCopyright: Copyright (C) 2014
OriginalFilename: Installer.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

PUA:Win32/InstallMetrix also known as:

BkavW32.FamVT.InstallMetrix.TTc.Worm
Elasticmalicious (high confidence)
DrWebTrojan.Domaiq.7
MicroWorld-eScanGen:Variant.Application.Bundler.DomaIQ.22
CAT-QuickHealPUA.Fileverifi.Gen
MalwarebytesGeneric.Malware.AI.DDS
ZillyaAdware.InstallMetrix.Win32.1
K7AntiVirusAdware ( 005875951 )
K7GWAdware ( 005875951 )
ArcabitTrojan.Application.Bundler.DomaIQ.22
VirITTrojan.Win32.Domaiq.H
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Adware.InstallMetrix.D
CynetMalicious (score: 100)
ClamAVWin.Adware.Installmetrix-5
Kasperskynot-a-virus:AdWare.Win32.InstallMetrix.a
BitDefenderGen:Variant.Application.Bundler.DomaIQ.22
NANO-AntivirusRiskware.Win32.InstallMetrix.digdoc
SUPERAntiSpywarePUP.InstallMetrix/Variant
AvastFileRepPup [PUP]
TencentMalware.Win32.Gencirc.10b2151b
EmsisoftApplication.InstallAd (A)
F-SecurePotentialRisk.PUA/InstallMet.hcs
VIPREGen:Variant.Application.Bundler.DomaIQ.22
FireEyeGeneric.mg.4b7b09a69ca64c00
SophosInstall Metrix (PUA)
IkarusPUA.InstallMetrix
JiangminAdWare/InstallMetrix.a
WebrootPua.Installmetrix
VaristW32/A-bb7f7afb!Eldorado
AviraPUA/InstallMet.hcs
Kingsoftmalware.kb.a.985
XcitiumApplicUnwnt.Win32.InstallMetrix.A@5jjix3
MicrosoftPUA:Win32/InstallMetrix
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.InstallMetrix.gen
GDataGen:Variant.Application.Bundler.DomaIQ.22
GoogleDetected
AhnLab-V3PUP/Win32.InstallMonster.R170192
VBA32Adware.InstallMetrix
ALYacGen:Variant.Application.Bundler.DomaIQ.22
TACHYONTrojan-Clicker/W32.InstallMetrix.1036416
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.97 (RDMK:Ou5Vr0iMaq2pNNfP3Rps5g)
MaxSecureVirus.W32.AdWare.Generic_227096
FortinetRiskware/Generic.AC.1A50E3
AVGFileRepPup [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove PUA:Win32/InstallMetrix?

PUA:Win32/InstallMetrix removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment