Malware

Downloader.Win32.DriverUpd malicious file

Malware Removal

The Downloader.Win32.DriverUpd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.DriverUpd virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

pool.ntp.org
analytics.auslogics.com
www.google-analytics.com

How to determine Downloader.Win32.DriverUpd?


File Info:

crc32: 04276E97
md5: 0b253d0ed491713203fcf9a9010a80f2
name: 0B253D0ED491713203FCF9A9010A80F2.mlw
sha1: 739026506ea067a8f751618e987c700e2e60fbcf
sha256: dcbb24e9dbdfe00024cdced609efd00723921441d946b9765cc73b2d592fea2b
sha512: ee6da180009495b53925712807a4ca5579fcaa9b3d764329f9d0b9983caf95132b47ff323f12e31ce90ac1d3983feb35336e3ad3ccc0e7a80a76c8af7a3bdb73
ssdeep: 6144:M062iQhfhvOpLSIUno2ZhlkZjDTBRHJRbGU+EHZCUaNgXZtQz9H5Fkv:M8iQhf9OpBvT3rNVZBaNgXZtWFkv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2008-2017 Auslogics Labs Pty Ltd
InternalName: driver-updater
FileVersion: 1.8.2.11
CompanyName: TweakBit
LegalTrademarks: Copyright xa9 2008-2017 Auslogics Labs Pty Ltd
Comments: Part of TweakBit Driver Updater
ProductName: Driver Updater
ProductVersion: 1.x
FileDescription: Driver Updater Setup
OriginalFilename: driver_updater_stub_installer.exe
Translation: 0x0409 0x04e4

Downloader.Win32.DriverUpd also known as:

FireEyeGeneric.mg.0b253d0ed4917132
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005329171 )
K7GWAdware ( 004f80461 )
Cybereasonmalicious.06ea06
CyrenW32/TweakBit.B.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Auslogics.A potentially unwanted
APEXMalicious
AvastWin32:SilentInstaller-A [PUP]
Kasperskynot-a-virus:HEUR:Downloader.Win32.DriverUpd.gen
AegisLabTrojan.MSIL.SpyGate.4!c
TencentMsil.Backdoor.Spygate.Eyf
SophosGeneric PUA HD (PUA)
ComodoApplication.Win32.Auslogics.AB@80idad
F-SecurePotentialRisk.PUA/TweakBit.Gen7
DrWebProgram.Unwanted.2042
ZillyaBackdoor.SpyGate.Win32.3486
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftApplication.InstallDrive (A)
JiangminRiskTool.Tweakbit.z
AviraPUA/TweakBit.Gen7
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Auslogics.a
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
SUPERAntiSpywarePUP.TweakBit/Variant
AhnLab-V3Trojan/Win32.SpyGate.R215173
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.DriverUpd.gen
GDataWin32.Application.Auslogics.C
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!0B253D0ED491
VBA32Backdoor.MSIL.SpyGate
MalwarebytesPUP.Optional.TweakBit
RisingPUF.Auslogics!1.AC47 (CLASSIC)
YandexTrojan.GenAsa!xeHao8lIpBI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Auslogics.A
AVGWin32:SilentInstaller-A [PUP]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.34a

How to remove Downloader.Win32.DriverUpd?

Downloader.Win32.DriverUpd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment