PUA

PUP.Optional.Conduit.DDS information

Malware Removal

The PUP.Optional.Conduit.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Conduit.DDS virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded pe malware family
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUP.Optional.Conduit.DDS?


File Info:

name: D35918168F8A35A019CF.mlw
path: /opt/CAPEv2/storage/binaries/74b6a8be9419827080faab10e039852ae003ead738dddad221fbd0b98806470e
crc32: EF503D01
md5: d35918168f8a35a019cf29901e122b3f
sha1: 07f657d0a31d3fad33107bc33a3ff3ae2af4c85a
sha256: 74b6a8be9419827080faab10e039852ae003ead738dddad221fbd0b98806470e
sha512: a49abfe4eed18bbd5e4c8abd8496acf4e433a6bc550e7c167b19addda72169bdf769a491ae7fbc85efb0c89bdc8278793f9cb22deb828da7e90f37dd61559193
ssdeep: 49152:60c24StiTTsdoNDjoJSFWWCycq1mFDbPd3Zm7BmKGMkO/VcmFJRUZYUxPIajLmED:636ivJDiSFdph1mPYAlO/hJ6ZYWvqnM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1170633298A24AAA3CFBC53744C30AF79F5927BEA801481DF8AD46C7E75DBDE4D147009
sha3_384: 88b24c9cc17db02edcf46078f9afd420d344bf7d3ca4974bee795f60cd53a711b7c674fed5c2e1267a492f6a3d38b069
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:53:13

Version Info:

0: [No Data]

PUP.Optional.Conduit.DDS also known as:

LionicAdware.Win32.BrowseFox.loBa
ClamAVWin.Trojan.Generic-9947499-0
SkyhighArtemis
McAfeeArtemis!D35918168F8A
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/Conduit.2be4e7e4
K7GWAdware ( 005403431 )
K7AntiVirusAdware ( 005403431 )
VirITPUP.Win32.Conduit.B
Elasticmalicious (high confidence)
ESET-NOD32Win32/iWin.A potentially unwanted
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Conduit.gen
NANO-AntivirusRiskware.Win32.Conduit.ennwge
AvastFileRepPup [PUP]
RisingAdWare.Win32.Nsia.a (CLASSIC)
EmsisoftApplication.Toolbar (A)
F-SecureAdware.ADWARE/Adware.Gen
DrWebAdware.Conduit.591
ZillyaAdware.BrowseFox.Win32.147422
SophosGeneric Reputation PUA (PUA)
IkarusPUA.iWin
GDataWin32.Trojan-Downloader.Murka.6L0C76
JiangminAdWare.Conduit.aaf
GoogleDetected
AviraADWARE/Adware.Gen
Antiy-AVLRiskWare[WebToolbar]/Win32.Conduit.b
XcitiumApplicUnwnt@#2wm0toctxip69
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Conduit.gen
VBA32Adware.Agent
MalwarebytesPUP.Optional.Conduit.DDS
TrendMicro-HouseCallTROJ_GEN.R002H07L323
YandexPUA.Conduit!j3lYSXEn3t4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/iWin
AVGFileRepPup [PUP]
DeepInstinctMALICIOUS

How to remove PUP.Optional.Conduit.DDS?

PUP.Optional.Conduit.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment