MosaicLoader malware: what it is and how to remove it

If you like using various downloaders or other ways to get software and games for free, chances are that one day you will download a virus as well. This new malware strain is advertised as a cracked software installer, but in reality, it is a dangerous downloader that can easily deliver any payload to the infected computer.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Unsure whether appsetup.exe is safe? A free scan checks the file and what starts it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove MosaicLoader malware yourself 6 steps, about 18 minutes, no software needed.

Start the steps
Screenshot of MosaicLoader malware: screenshot
MosaicLoader malware as our 2021 report showed it.

MosaicLoader malware: summary

NameMosaicLoader malware
TypeMalware, malware downloader
InfiltrationThis threat spreads through paid advertisements mostly
TraitsThis malware-delivery platform can deliver any threat to the infected system: remote-access trojans, Facebook cookie stealers, etc.
PreventionIf you want to avoid similar problems in the future, don't trust suspicious ads, avoid downloading files from unknown websites, and install software only from trusted sources
Detection namesNo Microsoft detection name is known
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 7 more facts
DistributionNot recorded in the old report
DamageNot recorded in the old report
SymptomsAn unknown process in Task Manager
Evidence4 write-ups by security sites; details still limited
File namesappsetup.exe and C:\Program
First seen26 July 2021
Facts checked6 October 2026

What MosaicLoader malware does on an infected PC

From our report of Jul 2021 · not reviewed since

More from our earlier report on MosaicLoader malware

  • One such infection is MosaicLoader malware which has been found by Bitdefender security experts.
  • To ensure your computer is malware-free, scan the system with a powerful security tool
  • That's why security experts from Bitdefender named it MosaicLoader.
  • The dropper downloads update-assets.zip from the C2 server (checkblanco[.]xyz in our run) into the %TEMP% folder.
  • The .zip file contains the two files required for the second stage, appsetup.exe, and prun.exe.
  • Then, the dropper extracts these files to C:\Program Files (x86)\PublicGaming\ and launches several instances of Powershell to add exclusions from Windows Defender for the folder and the specific file names.

What MosaicLoader malware can steal or download

From our report of Jul 2021 · not reviewed since

If you like using various downloaders or other ways to get software and games for free, chances are that one day you will download a virus as well.

This new malware strain is advertised as a cracked software installer, but in reality, it is a dangerous downloader that can easily deliver any payload to the infected computer.

According to experts, MosaicLoader malware is quite stealthy because it uses various tactics to hide from security experts and increase the likelihood of success to compromise the system. This infection tries to:

When a threat successfully enters a computer, it can cause many different types of problems. For example, it can easily infect the system with Facebook cookie stealers, remote-access Trojans, cryptocurrency miners, and other threats. This malware-delivery platform has been reported to target Windows users, but users of other systems should also be careful.

The main problem of this malicious downloader is its ability to severely affect user privacy. For example, if the malware sprayer successfully delivers Facebook cookie stealers on the system, these cookie stealers can exfiltrate login data, resulting in complete account takeovers, posts that spread dangerous malware, or other problems.

This malware downloader also spreads remote-access trojans - serious infections that can log keypresses on the system, capture screenshots, record audio from the microphone or images from the webcam, etc. When such important information is stolen, victims become extremely vulnerable as hackers can take over their accounts, attempt to blackmail them, and steal digital identities.

Once the threat is installed on the computer, it creates a complex chain of processes. This malware downloader has a unique obfuscation technique. It shuffles small code chunks around and creates a mosaic-like structure.

The first stage is quite simple: the dropper is installed on the system. These droppers try to mimic legitimate software and even have icons and version information or try to look like the NVIDIA process. Then, everything goes according to this plan:

The second stage is performed with a help of the appsetup.exe process. This process is used to attain persistence on the system. It tries to add a new registry value for another component - prun.exe.

After that, it registers itself as a "pubgame-updater". This way appsetup.exe process ensures that the persistence registry key will be added again even after the cleanup.

Then the prun.exe process is launched. This file is capable of transferring the execution of the malware from the main code section to a secondary one. Also, it uses difficult techniques and creates a mosaic-like structure to scramble the order of the chunks to be executed.

After that, prun.exe injects code into the process to communicate with the C2. It is necessary because C2 needs to download the final stage of this threat - a malware sprayer.

So, the purpose of the final stage is to download a list of malware and to successfully execute them. Using such tactics, various viruses can enter your computer.

  • Mimic file information to look like legitimate software;
  • Payload delivery mechanism infecting the system with several malware strains;
  • Code obfuscation with small chunks and shuffle execution order.
Screenshot of MosaicLoader malware: screenshot
MosaicLoader malware in our 2021 report.

How to check the PC for MosaicLoader malware

  • Path: C:\Program
  • File: appsetup.exe

How to remove MosaicLoader malware

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Check where appsetup.exe runs from and stop it

    In Task Manager (Ctrl + Shift + Esc) find appsetup.exe on Processes, right-click it and choose Open file location before ending anything.

    Windows' own files live in C:\Windows\System32; the same name in %AppData%, %Temp% or C:\Users\Public is an impostor. If the folder is wrong, right-click the process again, choose End task and delete the file.

    If it starts again within seconds, a task or another process restarts it, so run the scan step in Safe Mode. Task Manager works the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Close a frozen app (Task Manager, Force Quit) On uGetFix

  2. Step 2: Delete scheduled tasks that bring it back

    Programs like MosaicLoader malware add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  3. Step 3: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  4. Step 4: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after MosaicLoader malware, its publisher or created on the day the problem started.

    Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  5. Step 5: Scan the PC, then run the offline scan

    A scan finds the parts of MosaicLoader malware that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  6. Step 6: Change passwords from another device and sign out other sessions

    MosaicLoader malware can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

From our report of Jul 2021 · not reviewed since

How to avoid the malware: remember a few important rules

If you don't know how your computer got infected, try remembering if you haven't clicked on any ads recently.

This particular malware is rapidly spreading around the world through enticing ads in search results. Cybercriminals targeting users who are looking for pirated software or games but other users may also fall into similar traps.

That's why it's always important to think before clicking on any suspicious advertising that looks too good to be true. By clicking on such ads, you may be redirected to various unsafe pages and download infections. Also, never open suspicious emails, don't try to click on strange links you receive, etc.

And the most important rule is to always use a reliable antivirus program. Just keep in mind that it's important to update the security tool regularly.

From our report of Jul 2021 · not reviewed since

Don't forget to clean your computer

If your computer is infected by MosaicLoader malware, the best solution would be to remove it from your system immediately.

There is no reason why you should keep this threat on your computer, even if you downloaded it because of tempting advertising.

The ad is misleading and inaccurate because it's not a cracked software installer. As we mentioned before, it's just a downloader that can deliver any payload to an infected computer. So the longer you keep this malware downloader on your system, the greater the chance that the computer will be infected by more dangerous threats.

If malware is not letting you use antivirus in normal mode, access Safe Mode and perform a full system scan from there.

From our report of Jul 2021 · not reviewed since

Windows 7 / Vista / XP

  • Click Start > Shutdown > Restart > OK.
  • When your computer becomes active, start pressing the F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  • Select Safe Mode with Networking from the list.

From our report of Jul 2021 · not reviewed since

Windows 10 / Windows 8

Once you reach Safe Mode, launch or another reputable antivirus, update it with the latest definitions and perform a full system scan to eradicate malware and all its malicious components.

However, even after successful removal, you may still notice that your computer is performing worse than before. Since this downloader can deliver various types of threats to your computer, there is a good chance that some components performed changes within the Windows registry.

After these steps, your computer should work without serious interruption again. However, even though you have successfully removed the virus and cleaned the system, remember that you should be more careful from now on. Always use updated security software and do not download programs from suspicious pages.

  • Right-click on the Start button and select Settings.
  • On the left side of the window, pick Recovery.
  • Click Restart now.
  • Select Troubleshoot.
  • Go to Advanced options.
  • Select Startup Settings.
  • Click Restart.
  • Press 5 or click 5) Enable Safe Mode with Networking.
  • Download the application by clicking on the link above
  • Click on the ReimageRepair.exe
  • If User Account Control (UAC) shows up, select Yes
  • Press Install and wait till the program finishes the installation process
  • The analysis of your machine will begin immediately
  • Once complete, check the results - they will be listed in the Summary
  • You can now click on each of the issues and fix them manually

After removal: passwords, accounts and prevention

Accounts come next

Because the PC showed an unfamiliar process called appsetup.exe in Task Manager, a sign of a program that could read browser data, the clean-up is only half of the work.

The other half happens in your online accounts.

Change passwords from a clean device, beginning with e-mail; sign out of all sessions; check forwarding rules and recovery phone numbers; and turn on two-step verification with an authenticator app or a passkey. Ask your bank to replace cards saved in the browser.

Why the order matters and what to check in each account: secure your accounts after malware.

Do not let government spy on you

The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.

Avoid any unwanted government tracking or spying by going totally anonymous on the internet.

You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.

Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.

Backup files for the later use, in case of the malware attack

Computer users can suffer from data losses due to cyber infections or their own faulty doings.

Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.

When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.

Questions about MosaicLoader malware

Is appsetup.exe a virus?

The name appsetup.exe is not enough to say. Malware often uses technical-sounding names, and harmless updaters often use odd ones. Check three things:

  • the folder the file runs from
  • the Digital Signatures tab in its properties
  • the program that starts it (Startup apps, Task Scheduler or services)

A signed file from a company whose product you use is almost certainly fine. An unsigned file in a user folder that no installed program explains should be removed, and the PC scanned with Microsoft Defender in offline mode.

appsetup.exe keeps coming back. What should I do?

A process that returns after you end it has a restart mechanism, and that is a reason to treat appsetup.exe as unwanted. Check Settings > Apps > Startup, Task Scheduler and the Services list for entries pointing to its folder, and disable them.

Look in Installed apps for anything added the same day and uninstall it. Then delete the folder and run a Microsoft Defender Offline scan, which works before Windows starts and can remove files that are locked or hidden while the system is running.

Should I report MosaicLoader malware?

Report it if you lost money, if accounts were taken over, if you are a business, or if the trojan came through a scam call. A police or national cybercrime report gives you a reference number for your bank and insurer and helps link cases.

You do not need to report a trojan that antivirus blocked before it ran. Before reporting, write down the dates, the detection name, file names and any messages or transactions linked to the attack; screenshots of antivirus alerts are useful evidence. The country list is in the report section above.

How do I know if my PC has MosaicLoader malware?

Often you do not, which is the point of a trojan. Possible signs are an antivirus alert naming MosaicLoader malware or a generic trojan detection, unknown programs or scheduled tasks, processes with random names in Task Manager, browser extensions you did not add, security settings turned off, slower performance, or account alerts about logins from unknown places.

The reliable check is a full scan followed by Microsoft Defender's offline scan. If you recently ran a crack, a fake installer or a command a website told you to paste, scan even without symptoms.

Do I need to reinstall Windows to get rid of MosaicLoader malware?

Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see an unfamiliar process called appsetup.exe in Task Manager again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.

Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.

Should I check my other computers too?

Yes, it takes little time and removes doubt. MosaicLoader malware itself usually stays on one PC, but the download that carried it may have been copied to other computers, shared drives may hold the same installer, and an attacker who had access could have tried saved passwords on other devices.

Run a full scan on every Windows PC in the home or office, check shared folders for the original download, and change Wi-Fi and router passwords if they were stored on the infected machine.

Which malware family is MosaicLoader malware?

That is not known yet. MosaicLoader malware has been reported by people who saw an unfamiliar process called appsetup.exe in Task Manager, but no sample has been analysed publicly, so security companies have not assigned it to a family. The name you see may be a file or program name chosen by the authors, not a family name.

This does not stop you from removing it: the startup points, the offline scan and the account steps are the same for most families of this type. If Microsoft Defender or another scanner gives the file a detection name, write it down; that name is the best clue to the family and is useful when you report the incident.

My antivirus was on. How did a trojan get past it?

Antivirus programs see a file only when it is written or run, and criminals test each new build against popular scanners before release. Detection catches up within hours or days, which is often after the first victims ran it.

Archives with passwords, installers that fetch the malware later, and scripts run through PowerShell make the job harder. That is why behaviour such as downloading cracks or pasting commands matters more than any setting. Keep Windows and Defender updated, and turn on Reputation-based protection in App & browser control.

How dangerous is MosaicLoader malware?

Treat it as serious until proven otherwise. The visible sign is an unfamiliar process called appsetup.exe in Task Manager, and programs that behave this way often have more abilities than they show:

  • copying passwords
  • downloading other malware
  • giving remote access

Its family is not known yet, so nobody can say which of these it uses. The good news is that the response is the same in every case and takes about an hour:

  • cut the network
  • remove the startup entry
  • run an offline scan
  • change passwords from a clean device

If someone had remote control, a full reset is safer.

Will Fortect remove MosaicLoader malware?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For MosaicLoader malware, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Questions and experiences: MosaicLoader malware

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year