PUA

PUP.Optional.BSDownloader removal guide

Malware Removal

The PUP.Optional.BSDownloader is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.BSDownloader virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine PUP.Optional.BSDownloader?


File Info:

name: DC5C82C78CAA72773BD1.mlw
path: /opt/CAPEv2/storage/binaries/c12fb2ac5221b9e950a746f9e2ed2e2c491c3e2b8009fd6d3cb03706d2ba817c
crc32: D44D9EAC
md5: dc5c82c78caa72773bd128d1f2c59050
sha1: 7777fbff879ffabdd4c7a4fdc9f1aa9aee42656b
sha256: c12fb2ac5221b9e950a746f9e2ed2e2c491c3e2b8009fd6d3cb03706d2ba817c
sha512: 3369c6691d13deb844cd23c9a1b050aff5823a49afc08e676b3c603dbb4dd0ac1c80ba491a827477fe3a11120310b7a2f97f24fce313024b4c0a2758b9c72443
ssdeep: 12288:OZ5vrSGq8r8bH12zt9kIl7lVTMtmx+s9Er2cDsFr+ZiltVBOlvVG7gBllggGW5HJ:OT3lYb8zIXYrFrFsSQdrVxjeO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163E49E13B3CBC076D1B221B1595E6B37AA77BA00573285C766D41A8E6E306F14F3E392
sha3_384: 07f548fe589ac58c84b8ab28465779d77bbfa8709dfb157b37fb18d3326cd70b408d451598ace0232a0cb7e634f3e5a0
ep_bytes: e805050000e937fdffffcccccccccccc
timestamp: 2013-03-28 03:24:33

Version Info:

FileDescription: BSdownloader Module
FileVersion: 1, 0, 0, 3
InternalName: BSdownloader
LegalCopyright: Copyright 2011
OriginalFilename: BSdownloader.exe
ProductName: BSdownloader Module
ProductVersion: 1, 0, 0, 3
Translation: 0x0409 0x04b0

PUP.Optional.BSDownloader also known as:

Elasticmalicious (high confidence)
DrWebProgram.BrotherSoft.18
FireEyeGeneric.mg.dc5c82c78caa7277
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
ZillyaAdware.BrowseFox.Win32.135260
SangforRiskware.Win32.Wacapew.C
CyrenW32/BrotherSoft.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/BSDownloader potentially unwanted
TrendMicro-HouseCallPUA.Win32.BSDownloader.SMCGR06
NANO-AntivirusRiskware.Win32.BrotherSoft.ebqakp
ViRobotAdware.Bsdownloader.673976.I
SophosGeneric ML PUA (PUA)
F-SecurePotentialRisk.PUA/DownBro.Gen7
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win32.BSDownloader.SMCGR06
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.BSDownloader.B
JiangminDownloader.Agent.ljp
MaxSecureTrojan.not.a.virus.WIn32.Bsdownloader.b_188355
AviraPUA/DownBro.Gen7
SUPERAntiSpywarePUP.BSDownloader/Variant
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 99)
VBA32Downloader.Agent
MalwarebytesPUP.Optional.BSDownloader
APEXMalicious
YandexRiskware.BSDownloader!L56VwuDdWRE
IkarusPUA.Downloader
FortinetRiskware/BSDownloader
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUP.Optional.BSDownloader?

PUP.Optional.BSDownloader removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment