PUA

PUP.Optional.Downloader.DDS removal tips

Malware Removal

The PUP.Optional.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Downloader.DDS virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUP.Optional.Downloader.DDS?


File Info:

name: 4BF2CAEBE02EAA25141C.mlw
path: /opt/CAPEv2/storage/binaries/5b42b08e93598a17c5defe07e8211e88dd9814e22882114eaf049be07e333c7e
crc32: 92231E65
md5: 4bf2caebe02eaa25141c784e34b347f7
sha1: f019c1c3bf364d0d627a84741f9764544873f270
sha256: 5b42b08e93598a17c5defe07e8211e88dd9814e22882114eaf049be07e333c7e
sha512: fc872cc96671068eb5c8e811fcdaf46b71a2a701b480431686046fe4fbf4f5c1cabc141fba0bdb042a4cf40726f20e248d7036d465a9ce1fe15a10be4a0da06a
ssdeep: 24576:LcFQ71b5quRy55+3O4wYhz/DgK6Jo658NT0:LWw11qr5+3O4RNrgrraI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1910523A7D6A00835F09216B55F48801AEA37BA617F751E6835CC76FB875B7B0C8087CA
sha3_384: 6bd2a897da208d57ca12aaf888be625d47d22436678607beb78010b3f5c5d428773873ec705e57b6df8bcdc5cc8e38b3
ep_bytes: 5589e183c4c45356e9fb990000000000
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Program
FileDescription: Prog Setup
FileVersion: 2.8.5.5
LegalCopyright: App internet
ProductName: Prog
ProductVersion: 4.3.1
Translation: 0x0000 0x04b0

PUP.Optional.Downloader.DDS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.InstallCore.1903
MicroWorld-eScanApplication.DealAlpha.1.Gen
ClamAVWin.Malware.Installcore-6954484-0
FireEyeApplication.DealAlpha.1.Gen
CAT-QuickHealPUA.Dmnpartner.Gen
McAfeeRDN/Generic PUP.x
MalwarebytesPUP.Optional.Downloader.DDS
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.be02ea
VirITPUP.Win32.DMN.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/InstallCore.AFF.gen potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.InstallMonster.k
BitDefenderApplication.DealAlpha.1.Gen
NANO-AntivirusVirus.InnoSetup.Gen.ccng
SUPERAntiSpywarePUP.InstallCore/Variant
AvastWin32:Evo-gen [Trj]
TencentAdware.Win32.InstallCore.ka
EmsisoftApplication.DealAlpha.1.Gen (B)
F-SecurePotentialRisk.PUA/InstallCore.JF
VIPREApplication.DealAlpha.1.Gen
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Application.InstallCore.EU
JiangminDownloader.InstallMonster.dc
AviraPUA/InstallCore.JF
MAXmalware (ai score=85)
ArcabitApplication.DealAlpha.1.Gen
ViRobotAdware.Installcore.820808.RA
ZoneAlarmnot-a-virus:Downloader.Win32.InstallMonster.k
GoogleDetected
AhnLab-V3Adware/Win.Generic.R560671
Cylanceunsafe
TrendMicro-HouseCallPAK_Xed-21
MaxSecureAdware.not-a-virus.WIN32.AdWare.DealPly.gen_188964
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUP.Optional.Downloader.DDS?

PUP.Optional.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment