Malware

Downloader.MSIL.DownloadSponsor.tv removal

Malware Removal

The Downloader.MSIL.DownloadSponsor.tv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.MSIL.DownloadSponsor.tv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Anomalous binary characteristics

How to determine Downloader.MSIL.DownloadSponsor.tv?


File Info:

name: 47DAD3D8555CC2EF63D9.mlw
path: /opt/CAPEv2/storage/binaries/e788f11d18e676413b5849faf675085ff5c48e0ec5c8817710de01737464408c
crc32: B2CE0CCC
md5: 47dad3d8555cc2ef63d975ba9a23b2b7
sha1: ccba85a20c2150e62c5fc933e9380b574e2c4bc7
sha256: e788f11d18e676413b5849faf675085ff5c48e0ec5c8817710de01737464408c
sha512: 399ed93cb801fc53861da2129d9e8a70b227938c16e62e2db00432fe7e4c95b681f9655b09fba774783f4a30b8aee5e56bc3ecd107bfb8181560478bedc00a0c
ssdeep: 24576:4q5TfcdHj4fmbpt2qv6zZPLKNMrAcSkozt+Ig4lrApNs:4UTsam/xvurACGrAM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8557B2526E85B08E0BE8B7944B1495043F5BE52D65AE30E3EED64EE3F32340CE65327
sha3_384: c01504e5861b7c26360ca81e438b53ad3dea4fd7e1a98180473a83406cd15a008f13c5da86399b50a9256449725e149a
ep_bytes: 60be008057008dbe0090e8ff57eb0b90
timestamp: 2019-10-29 14:45:04

Version Info:

FileVersion: 2.10.0.2
Comments: CHIP Secured Installer
FileDescription: CHIP Secured Installer
ProductVersion: 2.10.0.2
LegalCopyright: Copyright © 2019 Chip Digital GmbH
CompanyName: CHIP Digital GmbH
InternalName: CHIP Secured Installer
ProductName: CHIP Secured Installer
OriginalFilename: CHIP Secured Installer
Translation: 0x0407 0x04b0

Downloader.MSIL.DownloadSponsor.tv also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.47dad3d8555cc2ef
CAT-QuickHealDownloader.AutoIT.Agent.A
McAfeeArtemis!47DAD3D8555C
CrowdStrikewin/grayware_confidence_100% (W)
VirITAdware.Win32.Covus.DK
CyrenW32/DownloadSponsor.E.gen!Eldorado
SymantecPUA.DownloadSponsor
ESET-NOD32Win32/DownloadSponsor.C potentially unwanted
TrendMicro-HouseCallPUA.MSIL.DownloadSponsor.SMDR
ClamAVWin.Dropper.Miner-7086571-0
Kasperskynot-a-virus:Downloader.MSIL.DownloadSponsor.tv
NANO-AntivirusTrojan.Win32.DownloadSponsor.gfegvm
RisingPUF.DownloadSponsor!1.BE33 (CLASSIC)
SophosGeneric Reputation PUA (PUA)
ComodoApplication.Win32.DownloadSponsor.CDA@8i0u33
DrWebAdware.Covus.88
TrendMicroPUA.MSIL.DownloadSponsor.SMDR
McAfee-GW-EditionBehavesLike.Win32.DLSponsor.th
EmsisoftApplication.AdLoad (A)
JiangminDownloader.MSIL.ouq
Antiy-AVLTrojan/Generic.ASCommon.1B7
MicrosoftPUADlManager:Win32/DownloadSponsor
SUPERAntiSpywarePUP.ChipInstaller/Variant
GDataWin32.Application.DownloadSponsor.R
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DownloadSponsor.R296839
Acronissuspicious
VBA32TScope.Trojan.MSIL
MalwarebytesPUP.Optional.ChipDe
IkarusPUA.DownloadSponsor
MaxSecureDownloader.MSIL.DownloadSponsor.gen
FortinetAutoIt/Dloader.SM!tr

How to remove Downloader.MSIL.DownloadSponsor.tv?

Downloader.MSIL.DownloadSponsor.tv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment