PUA

Should I remove “PUP.Optional.Proinstall”?

Malware Removal

The PUP.Optional.Proinstall is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Proinstall virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine PUP.Optional.Proinstall?


File Info:

name: 364ABBCE92F6E2E3B64A.mlw
path: /opt/CAPEv2/storage/binaries/5337858bc48b4096914453b23fe336c5ad565b29f0969920a28e2a84193be7ad
crc32: 21DF4445
md5: 364abbce92f6e2e3b64af0e10bd05daf
sha1: abf4efeb620d72f511589127babedb8c91b08ae2
sha256: 5337858bc48b4096914453b23fe336c5ad565b29f0969920a28e2a84193be7ad
sha512: c8635d66eaef717d633d581f1e8f9f5bc6e2840a229cd5eb20081f72216f5d6b08b9fb5a2c6c781baa92fec0487549ace7993230958b7be24dfb2e86030cdda1
ssdeep: 3072:gweqOYEUXPntyvd4e3pdUR6j9C0XmyDgEh4/oLXi:xEUX8lB3so00XmyDgi4/oLy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED34E925DE2C8044CFE19DF98AA9537DD3F150BC4C8C492BBDA61A61CE3788D746A732
sha3_384: 1793451286984f0273729f125f1fb57a1aad2813a6b31415e580d62a3357b0a4f27dab29e116a49b10dbeb8aaf0d8043
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:19:59

Version Info:

ProductVersion: 1.5
Translation: 0x0000 0x04b0

PUP.Optional.Proinstall also known as:

LionicTrojan.Win32.Genome.mjEC
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Generic.3027844
FireEyeGeneric.mg.364abbce92f6e2e3
CAT-QuickHealPUA.Proinstall.Gen
SkyhighArtemis!Trojan
McAfeeArtemis!364ABBCE92F6
Cylanceunsafe
VIPREAdware.Generic.3027844
SangforSuspicious.Win32.Save.ins
K7AntiVirusUnwanted-Program ( 00587b8e1 )
K7GWUnwanted-Program ( 00587b8e1 )
ArcabitAdware.Generic.D2E3384
VirITPUP.Win32.ProinstallApp.A
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win32/WinWrapper.A potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Generic-9941840-0
Kasperskynot-a-virus:Downloader.NSIS.Agent.wa
BitDefenderAdware.Generic.3027844
NANO-AntivirusTrojan.Win32.TrjGen.dwtece
AvastFileRepPup [PUP]
SophosGeneric ML PUA (PUA)
F-SecurePotentialRisk.PUA/WinWrapper.Gen
DrWebAdware.Downware.10477
ZillyaDownloader.Genome.Win32.54310
Trapminesuspicious.low.ml.score
EmsisoftApplication.Downloader (A)
WebrootPua.Adware.Proinstall
GoogleDetected
AviraPUA/WinWrapper.Gen
Antiy-AVLGrayWare/Win32.WinWrapper.b
XcitiumApplication.Win32.Winwrapper.D@6lncvq
MicrosoftPUABundler:Win32/YTDVideoDownload
ViRobotAdware.Winwrapper.232216.GA
ZoneAlarmnot-a-virus:Downloader.NSIS.Agent.wa
GDataWin32.Adware.ProInstall.C
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Downloader.R136354
VBA32Downloader.Agent
ALYacAdware.Generic.3027844
MAXmalware (ai score=62)
MalwarebytesPUP.Optional.Proinstall
PandaPUP/Multitoolbar
RisingAdware.WinWrapper!1.A3DA (CLASSIC)
YandexRiskware.Agent!y1WA96svLAE
MaxSecureVirus.W32.Downloader.Agent.gen_225498
FortinetRiskware/WinWrapper
AVGFileRepPup [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUP.Optional.Proinstall?

PUP.Optional.Proinstall removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment