PUA

PUADlManager:Win32/DownloadSponsor malicious file

Malware Removal

The PUADlManager:Win32/DownloadSponsor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/DownloadSponsor virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

www.c404.eu

How to determine PUADlManager:Win32/DownloadSponsor?


File Info:

crc32: 5830E78B
md5: 08a052ae7457bab41dc33bee245cc475
name: 08A052AE7457BAB41DC33BEE245CC475.mlw
sha1: e54148efa483c2dde3a04f0a6722f063e98b14d8
sha256: 6f975949489400b63547d505ea17999c2b1da56fd6754ab9bc7dd0c8888824ce
sha512: d78df72f96ab3056b0b7909aef376854c83b670b26952d89846d3b100210ab85d819a9081db269acf90fe2d5dda15b838ddc4ff05bfef3aa87b29c184ff8115f
ssdeep: 6144:cKQGYCYcMeg5DOD4K16rf0PL56cSyf4/rdD2PDl88888888bYR3Nwf9ysVufBn5:cbjegBO9P96cStQdOOysgfBnnl2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright @ www.download-sponsor.de
InternalName: ocsclient
FileVersion: 1.00
CompanyName: www.download-sponsor.de
Comments: OCSClient v5.0
ProductName: OCSClient
ProductVersion: 1.00
OriginalFilename: ocsclient.exe

PUADlManager:Win32/DownloadSponsor also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 004bc9fd1 )
Elasticmalicious (high confidence)
DrWebAdware.Downware.2424
CAT-QuickHealBackdoor.OCSClient.S270671
CylanceUnsafe
ZillyaDropper.Agent.Win32.229917
SangforTrojan.Win32.Occamy.C6F
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 004bc9fd1 )
Cybereasonmalicious.fa483c
CyrenW32/DownloadSponsor.F.gen!Eldorado
SymantecMobileInsightAppRisk:Generisk
ESET-NOD32a variant of Win32/DownloadSponsor.C potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusRiskware.Win32.Adw.dtkiwf
ViRobotAdware.Downloadsponsor.507904.C
TencentMalware.Win32.Gencirc.10bb1ef1
SophosGeneric ML PUA (PUA)
VIPREDownloadSponsor (fs)
McAfee-GW-EditionBehavesLike.Win32.Fareit.gh
FireEyeGeneric.mg.08a052ae7457bab4
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
AviraPUA/DownloadSponsor.Gen
Antiy-AVLTrojan/Generic.ASMalwS.149E2F9
KingsoftWin32.Heur.KVM006.a.(kcloud)
MicrosoftPUADlManager:Win32/DownloadSponsor
GDataWin32.Application.OCSClient.B
AhnLab-V3PUP/Win.Presenoker.R437228
McAfeeArtemis!08A052AE7457
VBA32Downware.VB.AndreClient
MalwarebytesPUP.Optional.DownloadSponsor
TrendMicro-HouseCallTROJ_GEN.R002H0CH521
YandexPUA.Downware!3rTvJ11Sr7I
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DownloadSponsor
Paloaltogeneric.ml

How to remove PUADlManager:Win32/DownloadSponsor?

PUADlManager:Win32/DownloadSponsor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment