Malware

Win32/FirseriaInstaller.A potentially unwanted removal guide

Malware Removal

The Win32/FirseriaInstaller.A potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FirseriaInstaller.A potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Win32/FirseriaInstaller.A potentially unwanted?


File Info:

name: 7221B9765619C0EEE062.mlw
path: /opt/CAPEv2/storage/binaries/9b3cb797a77cb7c104ea4587a00712fcb89bc67ff7f36197199a6ffdbdd30214
crc32: 8EA3BA82
md5: 7221b9765619c0eee06295a77a0309c6
sha1: 6330654532d328280430f4d30c109f00e9878ccc
sha256: 9b3cb797a77cb7c104ea4587a00712fcb89bc67ff7f36197199a6ffdbdd30214
sha512: 14f42111b09d32f3d7b97676e64844a2a224b8090f17b6e40c87effa6806708eff7b1b735dd3eee9122bfbd86d50ea3e98db2ca462c428684b4c62bd69a93b30
ssdeep: 6144:eVqOSY8NuhbUCQBrziWZ10aJDUgdHGxPLxm8ds44T:eqYdhgNBrzr10CdHGxzxpe4O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9A4F805535AD023DC07623E95F3C36E2B22E923A6167BC373980F365E266D53DA0BD9
sha3_384: 6cc40afbd5010b5707b582b97b5e5e17d5c499b68f2ae6b1bdce4355cf64c335a5f7fb8acdd2f90b8f1a199989e44619
ep_bytes: e8c5820000e989feffff8bff558bec8b
timestamp: 2013-11-05 09:25:02

Version Info:

CompanyName: Firseria·s·l
FileDescription: Download Manager
FileVersion: 1.0.0.19
InternalName: ·installer·
LegalCopyright: Copyright ©2013
OriginalFilename: installer·exe
ProductVersion: 3.0.23
Translation: 0x0000 0x04b0

Win32/FirseriaInstaller.A potentially unwanted also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Application.Bundler.Firseria.1
CAT-QuickHealDownloader.Solimba.12914
ALYacGen:Application.Bundler.Firseria.1
CylanceUnsafe
VIPREGen:Application.Bundler.Firseria.1
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.65619c
BaiduWin32.Adware.Firseria.a
CyrenW32/Firseria.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FirseriaInstaller.A potentially unwanted
APEXMalicious
ClamAVWin.Trojan.EmbeddedReversedDLL-9940922-0
Kasperskynot-a-virus:Downloader.Win32.Morstar.o
BitDefenderGen:Application.Bundler.Firseria.1
NANO-AntivirusTrojan.Win32.Morstar.cqrhat
AvastWin32:Morstar-D [PUP]
Ad-AwareGen:Application.Bundler.Firseria.1
EmsisoftGen:Application.Bundler.Firseria.1 (B)
DrWebTrojan.DownLoader10.51863
ZillyaDownloader.Firser.Win32.32
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7221b9765619c0ee
SophosSolimba Installer (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Application.Bundler.Firseria.1
JiangminDownloader.Firser.o
AviraHEUR/AGEN.1229029
Antiy-AVLTrojan/Generic.ASMalwS.330C
ArcabitApplication.Bundler.Firseria.1
MicrosoftPUADlManager:Win32/Solimba
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.FirseriaInstaller.R447449
McAfeeGenericRXAA-AA!7221B9765619
MAXmalware (ai score=78)
VBA32Downloader.Morstar
MalwarebytesPUP.Optional.Firseria
RisingAdware.FirseriaInstaller!1.9C53 (CLASSIC)
YandexTrojan.GenAsa!12uww/2GBas
IkarusPUA.FirseriaInstaller
MaxSecureTrojan.DownloadMR
FortinetAdware/Firseria
BitDefenderThetaGen:NN.ZexaF.34806.Cq1@a0r!crmi
AVGWin32:Morstar-D [PUP]
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Win32/FirseriaInstaller.A potentially unwanted?

Win32/FirseriaInstaller.A potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment