PUA:Win32/ICBundler: what the Defender alert means and how to remove it

PUA:Win32/ICBundler is the name Microsoft Defender gives to a potentially unwanted application, most likely an installer that bundles other software, and Microsoft does not count it as a virus. Find which file raised it and what came with it, then remove it in Windows Security and run a full scan.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a Microsoft Defender alert for PUA:Win32/ICBundler on a downloaded installer keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove PUA:Win32/ICBundler yourself 5 steps, about 15 minutes, no software needed.

Start the steps
A black Windows alert window titled PUA:Win32/ICBundler: Alert level Severe, Status Quarantined, Date 14/02/2021 10:26:55, Category Potentially Unwanted Software, Details This program is dangerous, and one blurred file path under Affected items, with an OK button
The alert from our 2021 guide: PUA:Win32/ICBundler, status Quarantined, category Potentially Unwanted Software, dated 14 February 2021. The file path is blurred in the picture. The title text and the red background were added by us. The wording 'Severe' and 'This program is dangerous' is how that 2021 alert read; the Microsoft Defender entry for the name shows no severity.

PUA:Win32/ICBundler: summary

TypeA Microsoft Defender detection name for a potentially unwanted application, most likely a bundling installer; not one program and not malware by Microsoft's definition
RiskLow to medium: the reports we read show blocked installers, not a trojan, but the extras that came with an installer you ran can be unwanted
SymptomsThe Defender alert, often the only sign; Microsoft lists slow performance and changed settings for the group; ads or redirects only if a bundled extra installed
How to get rid of itRemove the item in Protection history, delete the installer, uninstall what came with it, run a Full scan and a Microsoft Defender Offline scan
Our check (6 October 2026)No PC test: we read Microsoft's entry, its PUA and Offline scan pages, a Microsoft Q&A thread and a forum post; no installer was run
First seenMicrosoft entry published 11 December 2020; our first guide 23 February 2021; newest report we found November 2022
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
DetectionMicrosoft Defender: PUA:Win32/ICBundler, also written PUABundler:Win32/ICBundler in 2022 reports
Not to be confused withPUA:Win32/InstallCore, a separate Microsoft detection, and with the Mac or browser pop-ups in our old picture, which are not this detection
NamePUA:Win32/ICBundler
Evidence0 write-ups by security sites; details still limited
Microsoft Defender namePUA:Win32/ICBundler
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked6 October 2026

Facts checked on 6 October 2026 against Microsoft Security Intelligence, Microsoft Learn (PUA protection and Defender Offline), a Microsoft Q&A thread, a Windows 10 Forums post, Adobe's Flash end-of-life page and Microsoft's Internet Explorer lifecycle page.

We ran no installer and tested no PC; the removal steps follow Microsoft's pages and were not tried on a live infection, and the browser menu names were not rechecked today. A quiet result from any check does not clear a PC.

What PUA:Win32/ICBundler is, and what it is not

PUA:Win32/ICBundler is a detection name used by Microsoft Defender Antivirus, not the name of one program. It says Defender judged one file to be a potentially unwanted application, most likely an installer that carries other software with it. It does not say the file is a virus.

  1. 1

    What the name is

    Microsoft's own entry for the name is titled PUA:Win32/ICBundler, was published on 11 December 2020 and is marked as detected by Microsoft Defender Antivirus. It lists no aliases. Our 2021 guide called it an intrusive adware infection and a virus; Microsoft does not call it either.

  2. 2

    What Microsoft says about it

    Very little. The entry says technical details are currently not available. Its symptom list is the general one for the whole group: slow performance, added or modified files, changes in desktop settings, freezing or crashing, and less free storage. None of these is tied to this name in particular.

  3. 3

    What a PUA is

    Microsoft describes potentially unwanted applications as software that can make a PC run slowly, show unexpected ads or install other software you did not expect. Its examples are advertising software, bundling software that offers to install other programs, and evasion software. Microsoft adds that a PUA is not considered a virus or other malware.

  4. 4

    What the reports point to

    A helper on Microsoft's Q&A forum read the name as a software installer that bundles other apps, possibly from a torrent client. That is one volunteer's reading, not a Microsoft statement. The letters IC in the name are not explained anywhere we looked.

  5. 5

    What our 2021 guide got wrong

    It called the detection a virus, described pop-ups, banners and redirects that no source we read ties to this name, and sent readers to a paid anti-malware tool and a system tune-up tool. Defender is the tool that raised the alert and can handle it, and a tune-up tool repairs nothing a PUA changed.

Shown by
Microsoft Defender Antivirus (Windows Security). Forum posts also show it as PUABundler:Win32/ICBundler
Category
Potentially unwanted application, not malware by Microsoft's definition
Platform
Windows program files. Win32 does not mean your Windows is 32-bit
Is it one program?
No. Reports name a downloaded uTorrent.exe, a Logitech software install and an installer that came with Anaconda
Microsoft entry published
11 December 2020, with no update date and no technical details
Newest report we found
November 2022 on Microsoft's Q&A forum. Defender still carries the name, but we found no newer public report

So the useful questions are which file triggered the alert, whether it ran, and what came with it. The next chapters help you answer them.

What PUA:Win32/ICBundler does on an infected PC

How to read the alert, part by part

Microsoft's page does not explain the name, so the table separates what the words show from what we can only read into them.

Our reading of the Microsoft entry, Microsoft's PUA page and the pictures and threads listed under Sources. Microsoft does not describe ICBundler beyond its name.
PartWhat it showsWhat it does not show
PUA:The detection is for a potentially unwanted application. Microsoft says these notifications are prefaced with PUA:That the file is malware. Microsoft does not count a PUA as a virus
Win32/A Windows program fileThat your Windows is 32-bit
ICBundlerThe label Defender gave the file. A forum helper read it as an installer that bundles other appsWhat the file installs. Microsoft gives no technical details
PUABundler:The form some 2022 reports show, for the same nameA different threat; we found no description of a difference
Remove, Quarantine, Allow on deviceThe three choices in our 2021 picture for an active detectionThat any of them is needed if Defender already blocked the file
Status: FailedA 2022 reader's alert said the threat or app might not be fully remediatedThat the PC is infected. It means Defender did not finish the action

What we checked on 6 October 2026, and what we could not

There is no website to test here and we ran no installer. We read Microsoft's pages and the public reports that name the detection.

Our reading of the sources, 6 October 2026

  • The name is a real Defender detectionMicrosoft's Security Intelligence has an entry for PUA:Win32/ICBundler, published 11 December 2020. It is not an invented scam alert.
  • What the detection looks forNot documented. The entry says technical details are not available.
  • Which file is behind itDiffers per case: a file called uTorrent.exe in Downloads, a Logitech software install, and an installer that came with Anaconda. One name covers different files.
  • Blocked at download or installA volunteer Microsoft forum moderator wrote that if Defender blocked the installer, the PUA part was blocked from installing and the PC was safe, and that the installer can simply be deleted. That is one helper's view, not Microsoft's.
  • A bundled program that did installIn one 2022 case the reader traced the alert to Lavasoft's Web Companion, which came with Anaconda; the helper had named it from the alert. The reader cleaned the Temp folder and found nothing under the name afterwards.
  • Our 2021 claims about ads and redirectsNot confirmed. No source we read shows ICBundler itself displaying ads or redirecting a browser.
  • A quiet scan afterwardsDoes not clear the PC. A second scan that finds nothing is one data point, because scanners label files differently and some software hides from some of them.

Treat as an unwanted installer until you know the file The reports we read describe a bundling installer that Defender blocked, not a trojan. We saw nothing on any PC, and a quiet result is never proof. Find the file, check what came with it, then follow the check and removal chapters.

Where the name has been reported

These are the cases we could read. They show how different the files are. They are not a list of what your alert is.

Sources: Windows 10 Forums, Microsoft Q&A, Reddit search results. A report shows where the alert was seen, not what the file was.
CaseWhat the source saysHow it ended
uTorrent.exe in Downloads (23 February 2021)A reader's Windows 10 alert: Detected PUA:Win32/ICBundler, status Removed, file C:\Users\...\Downloads\uTorrent.exe. The file had been on the PC for about a day. He saw only the Allow action and could not tell if the file was goneThe replies in the thread did not answer; they quoted other readers' uTorrent installation problems
Installer with Anaconda (28 November 2022)A reader's alert showed the name with status blocked, not deleted. A helper named Lavasoft's Web Companion and pointed to the Temp folder; the reader traced it to a bundle with AnacondaThe reader deleted the Temp folder contents and found no trace of Lavasoft or Web Companion
Logitech software (28 November 2022)A reader installed Logitech Options and Options+, and four days later Defender showed PUABundler with status Failed and 'might not be fully restored'The thread has no verdict on that file
Reddit threads, around 2022Search results show posts titled 'Windows Defender is not deleting PUA:Win32/ICBundler' and 'PUAbundler:Win32\ICbundler virus? quarantine or delete it?'We read only the titles and excerpts, not the replies

How the name has turned up, 2020 to 2022

Microsoft's entry is from December 2020. Every public report we found is from February 2021 to November 2022.

  1. 11 December 2020

    Microsoft adds the entry

    The Security Intelligence page for PUA:Win32/ICBundler is published. It has no update date and no technical details.

  2. 12 February 2021

    The Windows Security entry in our guide

    A Windows Security entry for the name, level Low, with Remove, Quarantine and Allow on device.

    A Windows Security threat entry reading PUA:Win32/ICBundler, 2/12/2021 10:27 AM (Active), level Low, with action options Remove (selected), Quarantine and Allow on device, above a second scanner row named PUP.Optional.BundleInstaller, type Potentially Unwanted Program, with a woman pointing at it
    From our 2021 guide: the Windows Security entry for PUA:Win32/ICBundler, 12 February 2021, level Low, with the choices Remove, Quarantine and Allow on device. The row above it is a different name, PUP.Optional.BundleInstaller, from a scanner we could not identify. The woman and the background were added by us.
  3. 14 February 2021

    The alert window in our guide

    Our cover picture shows the same name as a quarantined item in the category Potentially Unwanted Software. Two days earlier the other picture shows level Low.

  4. 23 February 2021

    Our first guide, and a uTorrent report

    Our guide called the name an adware infection. The same day a reader on Windows 10 Forums posted an alert for a uTorrent.exe download.

  5. 25 to 29 November 2022

    Microsoft Q&A threads

    Readers asked if the PC was safe after PUABundler:Win32/ICBundler was blocked but not deleted, and two traced it to bundled installers.

  6. 2026

    No newer report found

    We found no public report newer than November 2022 in the sources we read. We could not tell if Defender still raises the name often.

What the old guide said about ads and redirects, checked

Our 2021 guide described adware: pop-ups, banners, redirects and tracking. The parts below separate what Microsoft says about PUAs from what nobody has shown for this name.

The left column is our 2021 text, reused as claims to check, not as facts.
Old claimWhat we foundOur reading
It shows pop-ups, banners, in-text links and sponsored search resultsMicrosoft lists advertising software among PUAs, but its entry for this name shows no ad behaviourNot confirmed for ICBundler. Ads, if you see them, usually come from a program that was installed with it
It redirects to affiliated sites, sometimes without a clickNo source we read shows thisNot confirmed. A redirect is a reason to check your browser, not proof of this detection
Adware does not change browser settings, a hijacker doesOur 2021 guide drew this line between the twoA fair description of the two kinds. Which one a bundled extra is must be checked on the PC
Ads show imaginary news and amazing dealsThis is how fake-update and bundle ads are writtenKept as a warning in the entry chapter
The PUP or its advertisers collect your browsing habitsMicrosoft's page lists no data collection for the nameNot confirmed. Treat it as a risk of bundled programs, not a fact about this file

What PUA:Win32/ICBundler can steal or download

What an unwanted installer can cost you

None of the reports we read shows a real infection behind the name. These are the risks of the bundled software, not of the detection.

  • Medium

    Other unwanted programs

    Microsoft defines bundling software as software that offers to install other software. Our 2021 guide warned the same: a bundle can bring more PUPs.

  • Medium

    Ads and redirects

    If an ad-showing program came along, you may see unwanted ads or sudden redirects. Our guide said ads can lead to pages with explicit or malicious content, so do not click them.

  • Medium

    Browsing data

    Our 2021 guide said the PUP or its advertisers can track your habits. Nothing we read shows ICBundler doing this; a bundled extra could.

  • Medium

    Lost privacy and more infections

    Our guide named loss of privacy and more infections as the cost of clicking deceptive ads. That holds for any bundled program you leave installed.

  • Low

    Slower PC

    Microsoft lists slow performance, changed settings and less free storage as signs of the PUA group. They can come from any unwanted program.

  • Low

    Nothing at all

    If Defender blocked the installer at download, the volunteer on Microsoft's forum said it never reached the PC. The danger is the case in which you ran it.

What you may notice, and what the sources show

The alert itself is often the only sign. Our 2021 guide listed more ads than usual, sudden redirects and a slower device; Microsoft's list is shorter.

Sources: Microsoft Security Intelligence entry, Microsoft Q&A, our 2021 guide.
SignWhat we found
The Defender alertThe usual and often the only sign. It came after a download or an install in every report we read
More ads than usual, sudden redirectsOur 2021 guide's sign. No source ties it to this name. If it happens, check your browser extensions, not only this file
Slow performance, changed settings, freezing, less storageMicrosoft's list for the PUA group. Not specific to this name
Crashing, lag, freezing, blue screensOur 2021 guide linked these to changes in system files. A blocked installer changes none; they are reasons to scan, not proof
The alert says Failed or comes backA 2022 reader's alert said the threat might not be fully restored. It means a leftover or a restart is needed; it does not prove infection
NothingAdware is made to stay quiet, which is why our 2021 guide called it a silent infection

How to check the PC for PUA:Win32/ICBundler

What antivirus programs call PUA:Win32/ICBundler

Microsoft Defender reports PUA:Win32/ICBundler as PUA:Win32/ICBundler.

In a Defender name, the part before the colon is the category, the part after it is the platform, and the part after the slash is the family Microsoft assigned. A suffix after ! is an internal Microsoft marker, not a different threat.

Generic labels such as Agent, GenericKD or Malware.AI only say that a file looks malicious, not what it does; our guide to antivirus detection names shows how to read them.

How a file like this gets onto a PC

Our 2021 guide named three routes: freeware bundles, deceptive ads and fake Flash updaters. Microsoft's PUA page describes the same trick.

  1. 1

    Freeware bundles

    Our guide said PUPs are delivered with software bundles in which all apps in the pack are preselected for installation. Microsoft calls this bundling software: it offers to install other software that is not signed by the same publisher.

  2. 2

    Custom or Advanced setup

    Our guide said to pick Custom or Advanced over Recommended, Quick or Standard, and to take your time. That still works: untick each extra, decline the offer, and close the installer if a page asks for a browser or search change you did not want.

  3. 3

    Deceptive ads

    We have all met misleading ads. They show an amazing deal or a tool that will speed up the internet and send you to a page that has nothing to do with the ad. The promised tools usually do nothing, or slow the device and bring more ads.

  4. 4

    Free software from copy sites

    The readers' cases involve a torrent client, an Anaconda download and Logitech software. A helper said the installer was possibly a torrent client. Take programs only from their makers' sites.

  5. 5

    Fake Flash updaters

    Adobe stopped supporting Flash Player on 31 December 2020 and blocked Flash content from 12 January 2021, and says unauthorised Flash downloads are a common source of malware. Any 'Flash update' offered to you now is not a real update.

Two Mac-style windows: Update Adobe Flash Player with an Install button and Adobe Flash Player Installer, version 10.1, with Later and Update buttons, over the title PUA:Win32/ICBundler
Our 2021 illustration for fake Flash updates: an 'Update Adobe Flash Player' window and an 'Adobe Flash Player Installer' window for version 10.1, both drawn with Mac-style window buttons. It is not a sample of ICBundler, and the detection itself is a Windows one. The title text was added by us.

The habits that cover all of them: install from the maker, read each installer screen, choose Custom, and keep Defender on.

Check your PC before you delete anything

Do not click Allow on device. Write down what the alert says first, then look at what is on the PC.

  1. 1

    Open Protection history

    Open Windows Security > Virus & threat protection > Protection history. Find the PUA:Win32/ICBundler entry and expand it. Note the status (Quarantined, Removed, Blocked, Failed), the date and the file path.

  2. 2

    Read the file name and folder

    A path in Downloads or Temp points to an installer. An installer you ran yourself, for example a torrent client or a utility, tells you which program carried it. Microsoft says a blocked PUA file is moved to quarantine and its notification starts with PUA:.

  3. 3

    Ask whether it ran

    If Defender blocked the file at download, the volunteer helper on Microsoft's forum said it never got to the PC. If you opened the installer, the bundled extras may have tried to install; check the next step.

  4. 4

    Look at what installed recently

    Open Settings > Apps > Installed apps and sort by install date. Note programs you did not choose, such as a browser, a 'companion', a coupon tool or a PC cleaner. In the Anaconda case the extra was Lavasoft's Web Companion.

  5. 5

    Look at what starts with Windows

    Press Ctrl + Shift + Esc and open Startup apps. Note names you do not know and the ones that started recently.

  6. 6

    Read every name in the report

    Write down every detection, not only this one. Other names beside it, for example PUA:Win32/InstallCore, which appears in Microsoft's own sample output, show what else was in the same file.

How to remove PUA:Win32/ICBundler

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like PUA:Win32/ICBundler add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after PUA:Win32/ICBundler, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of PUA:Win32/ICBundler that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    PUA:Win32/ICBundler can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Remove it from Windows 11 and Windows 10

Do the steps in order and stop when a full scan is clean and the alert has not returned. We did not run these steps on a live infection; they follow Microsoft's pages. Microsoft Defender is the program that found the file, and it is enough for this detection.

  1. 1

    Remove the item in Protection history

    In Protection history open the PUA:Win32/ICBundler entry and choose Remove. If you see only Allow on device, as the uTorrent reader did, close the window and run the scan in the next step instead. Do not choose Allow.

  2. 2

    Delete the installer

    Delete the installer you downloaded, for example from Downloads, and empty the Recycle Bin. The Microsoft forum helper's advice for a blocked installer was the same: if you have the installer, delete it.

  3. 3

    Uninstall what came with it

    Open Settings > Apps > Installed apps, find the programs you noted, choose the three dots and Uninstall. Do this for any browser, companion or cleaner you did not pick.

  4. 4

    Clear leftovers in Temp

    The Microsoft helper told the Anaconda reader to empty the Temp folder. Do it with Settings > System > Storage > Temporary files, or delete only the file Defender listed, rather than everything by hand.

  5. 5

    Run a full scan

    Update Windows Security first. Then open Virus & threat protection > Scan options, choose Full scan and click Scan now. Our 2021 guide said to run a full system scan and follow the security software's recommendations; that is still right.

  6. 6

    Run a second opinion with Microsoft Defender Offline

    In Scan options choose Microsoft Defender Offline scan and click Scan now. Microsoft says it takes about 15 minutes, restarts the PC and runs outside the normal Windows kernel. Save your work first. If BitLocker is on, Microsoft says to suspend it first. Afterwards read Protection history.

  7. 7

    Check the status again

    If the entry still says Failed or Active after a restart, scan again and then run the offline scan. If it keeps returning, the installer or a bundled program is still on the PC.

After a clean scan you do not need a tune-up or optimizer tool. Our 2021 guide recommended one for 'repairing' system damage; we found no damage to repair and no source showing such a tool fixes it.

If you see ads or changed settings: check your browser

Our 2021 guide said the adware mainly affects Chrome, Firefox and Edge. That belongs to the programs bundled with the file, not to the detection, so do this only if you see ads, redirects or a changed start page. These menu names are the browsers' own as we know them; we did not recheck them today.

Internet Explorer is not listed: Microsoft retired the IE 11 desktop app on 15 June 2022. Mac and Safari are not listed because Win32 is a Windows detection.
BrowserExtensions to look atReset
Google ChromeMenu (three dots) > Extensions > Manage extensions. Remove any you did not installSettings > Reset settings > Restore settings to their original defaults
Microsoft EdgeMenu > Extensions > Manage extensions. Remove any you do not knowSettings > Reset settings > Restore settings to their default values
Mozilla FirefoxMenu > Add-ons and themes > Extensions. Remove any you do not knowMenu > Help > More troubleshooting information > Refresh Firefox
  1. 1

    Clear cookies from the browser, not with a tool

    Our guide told readers to use an optimizer to wipe tracking cookies. The browser can do it: open its settings, find Delete browsing data or Clear data, and select cookies and site data.

  2. 2

    Turn on PUA blocking in Edge

    Microsoft says Chromium Edge can block potentially unwanted app downloads. Open Settings > Privacy, search, and services and under Security turn on Block potentially unwanted apps.

Could it be a false alarm? When to restore or allow

Possibly, but a PUA detection is not a claim of malware, so the question is rather whether you want the program. Microsoft says a file blocked by PUA protection can be added to an exclusion list when a task needs it.

Not a test. These are signs from the cases we read.
Points to a bundled or unwanted installerPoints to a program you wanted
The file came from a copy site, a torrent or an adThe file came from the maker's own site
The file is an installer that offers extrasThe file is the program itself, not an installer
Other detections appear next to itOnly one detection, and the PC works normally
New programs, extensions or a changed browser appearedNothing new appeared
The alert returns after you remove itThe alert came once and stayed quarantined
  1. 1

    Do not allow it first

    Allow on device lets the file run. If you want the program, download it again from its maker's site, choose Custom setup and decline the extras.

  2. 2

    Exclusions are the last step

    Microsoft documents exclusions by file extension and folder location. Add one file, never a whole folder such as Downloads.

  3. 3

    Test with audit mode, if you manage the PC

    Microsoft says PUA protection has an audit mode that detects without blocking, and events are logged under event ID 1160. It is meant for companies checking their software.

After removal: passwords, accounts and prevention

Secure your accounts after the clean-up

Assume that whatever was saved in the browsers on this PC while the PC showed A Microsoft Defender alert for PUA:Win32/ICBundler on a downloaded installer in the list of installed apps has been copied:

  • passwords
  • cookies
  • autofill data

Work from a clean device, or from this PC once the offline scan finds nothing.

Start with your main e-mail account, because it can reset everything else, then banking and payment, then social and gaming accounts. Change each password, sign out of all sessions and turn on two-step verification: Turn on two-step verification / secure a hacked account.

The full order, including crypto wallets and card replacement, is in securing your accounts after malware.

If you ran the installer or clicked an ad

The scans above deal with the file. These steps deal with what the extras could have done.

  1. 1

    Uninstall the extras

    Do the Installed apps step again, with the install date of the installer as your guide, and remove everything that arrived with it.

  2. 2

    Do not follow what the ad asked

    Our guide said that clicking can lead to explicit, malicious or other shady pages. Close the tab. Do not enter passwords or card details on a page an ad opened.

  3. 3

    Change passwords from another device

    If you typed passwords or card details after the installer ran, change the email password first, then banking, and turn on two-step sign-in.

  4. 4

    Check browser settings

    If the homepage, new tab page or search engine changed, remove the extension and reset the browser as in the browser chapter.

  5. 5

    Scan again in a week

    Run a full scan and a Defender Offline scan a week later. Keep a screenshot of the first alert.

Keep unwanted installers off your PC

The advice from 2021 still holds: pick Custom setup and do not click deceptive ads. Here it is with current details.

Do

  • Choose Custom or Advanced in an installer and untick every extra. Take your time on the offer screens.
  • Download programs from their makers' sites or the Microsoft Store.
  • Keep Microsoft Defender or another security product on with real-time protection, and let it update.
  • Keep Block potentially unwanted apps on in Edge, and keep PUA protection on in Windows Security.
  • Keep a backup of your documents on a disk you unplug (File History or OneDrive). This replaces our 2021 data-recovery tool advice.
  • Install Windows Update monthly, and update your browser.

Don't

  • Do not click pop-ups, banners or ads that promise news, deals or a speed-up. Our 2021 guide said they should never be clicked.
  • Do not install a Flash update. Flash ended in 2020 and no real update exists.
  • Do not use installers from copy sites, torrent portals or cracks.
  • Do not click Allow on device to make an alert go away.
  • Do not buy a cleaner or tune-up tool because an alert told you to.

Questions about PUA:Win32/ICBundler

What is PUA:Win32/ICBundler?

It is a detection name used by Microsoft Defender Antivirus for a potentially unwanted application, most likely an installer that bundles other software. Microsoft's entry, published on 11 December 2020, lists no aliases and says technical details are not available. A volunteer on Microsoft's forum read it as a software installer that bundles other apps, possibly a torrent client.

The name covers different files in different reports, so it is not one program. Treat the alert as a prompt to find out which file raised it, whether it ran and what came with it, not as the name of a single infection you can look up.

Is PUA:Win32/ICBundler a virus?

No, by Microsoft's own definition. Microsoft says a potentially unwanted application is not considered a virus, malware or other threat, although it can slow the PC, show unexpected ads or install other software. Our 2021 guide called it an adware infection and a virus, and we have corrected that.

A PUA can still bring unwanted extras, so do not ignore the alert. Check which file was flagged, whether you ran it and what installed beside it. A quiet result from one scan does not clear a PC, because scanners label files differently.

How do I remove PUA:Win32/ICBundler from Windows 11 or 10?

Open Windows Security, go to Virus & threat protection and Protection history, and choose Remove on the entry. Delete the installer from Downloads, then uninstall programs that came with it in Settings, Apps, Installed apps.

Run a Full scan from Scan options, and then a Microsoft Defender Offline scan as a second opinion; Microsoft says it takes about 15 minutes and restarts the PC.

Do not click Allow on device. If the entry says Failed, restart and scan again. We did not run these steps on a live infection; they follow Microsoft's pages.

Is my computer safe if Defender blocked it but did not delete it?

Most likely, but not proven. A volunteer moderator on Microsoft's forum wrote that if Defender blocked the installer at download, it never reached the PC, and that if it was run, the PUA part was blocked from installing. That is one helper's view, not Microsoft's statement.

Check Protection history for the status, delete the installer and look in Installed apps for anything you did not choose. If you ran the installer, run a Full scan and the offline scan as well. A status of Failed means the action did not finish, so scan again.

Why did uTorrent.exe trigger PUA:Win32/ICBundler?

One reader reported it in February 2021 for a file named uTorrent.exe in his Downloads folder, with status Removed and only the Allow action offered. We cannot tell from the post whether that file was the real installer or a copy.

Installers that bundle extra software are a known source of this kind of alert, and the Microsoft forum helper said the detection looked like a bundling installer, possibly a torrent client. Download programs only from their makers' sites and choose Custom setup so extras can be declined.

Should I click Allow on device?

No, unless you have confirmed the file is something you want. Allow on device lets a detected file run, and our 2021 picture shows it next to Remove and Quarantine.

If you want the program, download it again from its maker's site, decline the extras in a Custom setup, and add an exclusion for one file only as a last step. Microsoft documents exclusions by file extension and folder location. Never exclude a whole folder such as Downloads to silence an alert.

Why does PUA:Win32/ICBundler keep coming back or say Failed?

A Failed status or a repeat alert usually means a copy of the installer is still on the PC, or a bundled program recreates it.

A 2022 reader's alert said the threat might not be fully restored. Delete every copy of the installer, empty the Recycle Bin, remove programs that arrived with it in Installed apps, restart and run a Full scan.

Then run the Microsoft Defender Offline scan. If a Temp folder holds the file, clear temporary files in Settings, System, Storage. A repeat alert does not prove an infection.

Do I need to buy anti-malware or a system tune-up tool?

No. Our 2021 guide told readers to buy a professional anti-malware tool and a system tune-up tool, and we have dropped that. Microsoft Defender raised the alert, can remove the item, and has a free offline scan.

A tune-up tool repairs nothing a PUA installer changed, and no source we read says otherwise. If you want a second scanner, pick one by its own tests, not because an alert recommends it. Spend the effort on checking Installed apps and your browser extensions.

Does it affect Chrome, Firefox, Edge or Mac?

The detection is for Windows files, not for a browser. Our 2021 guide said the adware mainly affects Chrome, Firefox and Edge, but the browser trouble comes from programs that were bundled with the installer, if any.

Check each browser's extensions and reset it only if you see ads, redirects or a changed start page. Mac and Safari are not covered: Win32 is a Windows label, and the Mac-style Flash windows in our old picture were an illustration, not a sample. Internet Explorer 11 was retired on 15 June 2022.

Will Fortect remove PUA:Win32/ICBundler?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For PUA:Win32/ICBundler, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Questions and experiences: PUA:Win32/ICBundler

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,452 members already hereReading, writing, commenting and voting. 0 verified · 177 joined this year