GRIDINSOFT HELP CENTER

Potentially Unwanted Program (PUP/PUA): Detection and Removal

A potentially unwanted program (PUP) or potentially unwanted application (PUA) is software whose behavior, installation method, or business model may be undesirable even when it is not classified as outright malware. Security vendors use the two terms almost interchangeably. A PUP/PUA detection describes a risk category, not one specific virus.

Common examples include adware, browser extensions that change search settings, software bundles, aggressive system cleaners, cryptominers installed without clear consent, and tools that evade an informed uninstall. The important question is not simply “Is this file malicious?” but “Did the user knowingly choose this behavior and can they control it?”

PUP/PUA vs. malware, adware, and riskware

  • Malware is designed for unauthorized or harmful activity, such as stealing data or encrypting files.

  • PUP/PUA may have a stated function but uses poor consent, deceptive promotion, excessive advertising, or unexpected system changes.

  • Adware is advertising-supported software; it may be detected as PUA when the ads, tracking, or installation are intrusive.

  • Riskware or hacktools can have legitimate administrative uses but become dangerous in the wrong context. Authorization and source matter.

A detection is therefore contextual. A remote-management tool approved by an IT team is different from the same tool silently installed by an unknown downloader. Do not create a broad security exclusion merely because a program has a recognizable name.

Why security tools block PUA

Microsoft and other vendors evaluate factors such as misleading consent, bundled offers, advertising behavior, browser modification, reputation, and whether an app can be cleanly removed. A blocked download may never have run, while a detection inside an installed program means you should also inspect the parent installer and related components.

Typical warning signs are:

  • new extensions, search providers, notifications, or home-page changes;

  • ads appearing outside the browser or on sites that normally have none;

  • unknown startup entries, scheduled tasks, updaters, or background processes;

  • a “free” installer that used preselected offers or a misleading Express button;

  • repeated cleanup alerts because a downloader or browser sync restores the item.

What to do after a PUP or PUA detection

  1. Read the detection location and action. If the item was blocked in Downloads and never opened, delete the installer and empty the browser download list. If it was quarantined from an installed application, continue with the steps below.

  2. Identify the source. Note what was installed at the same time. Remove the original bundle, unfamiliar companion apps, and unnecessary updaters through the operating system's normal uninstall controls.

  3. Review browsers. Remove unknown extensions, revoke unwanted notification permissions, and restore the home page and search engine. If browser sync restores the extension, remove it from the synced account as well.

  4. Run an updated full scan. Quarantine detected components. A second-opinion scan is reasonable when symptoms continue, but avoid running multiple real-time antivirus engines simultaneously.

  5. Restart and scan again. A recurring detection often points to a scheduled task, another installer, cloud sync, or a browser extension that was not removed.

What if the software is approved?

Confirm the publisher, digital signature, download source, file path, and business owner. Compare the hash or installer with the vendor's official release. In a managed environment, ask the security team to review the exact detection. If an exception is justified, scope it to the specific signed file or managed deployment rather than excluding an entire folder or disabling PUA protection.

If the publisher is unknown, the signature is invalid, or the program arrived through a crack or unofficial mirror, treat the alert as meaningful. Uninstall it and inspect the system for additional payloads.

How to prevent unwanted programs

  • Download software from its official publisher or a trusted app store.

  • Keep PUA blocking enabled for both downloaded files and installed applications.

  • Choose Custom installation and reject unrelated offers.

  • Avoid cracks, “codec updates,” download wrappers, and pop-up system cleaners.

  • Review installed apps and browser extensions periodically.

PUP/PUA FAQ

Is a PUP a virus?
No. PUP/PUA is a broader, lower-confidence risk classification, although unwanted software can expose a device to malware or serious privacy problems.

Should I allow a PUA detection?
Only after verifying the exact file, publisher, source, purpose, and authorization. Familiar branding alone is not enough.

Why does the alert return after removal?
The source may remain in a bundled installer, browser sync, scheduled task, another user profile, or a restore location. Use the detection path to find what recreates it.

For Microsoft's current classification and blocking guidance, see its pages on malware and PUA evaluation criteria and potentially unwanted application protection.

Helpful?

Glossary (0-9, A-Z)

Still can’t find an answer?

Send us a ticket and we will get back to you.

Submit a ticket