PUA

PUP.Optional.DownloadSponsor removal tips

Malware Removal

The PUP.Optional.DownloadSponsor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.DownloadSponsor virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUP.Optional.DownloadSponsor?


File Info:

crc32: CCB98B8B
md5: 221d2f1f99767ddbfe0bdaef0d1fc458
name: 221D2F1F99767DDBFE0BDAEF0D1FC458.mlw
sha1: 4f3bc5d6c51b9b782d07603c3f793e1627b88730
sha256: dd6b3edd68cc5fe0754860ea05758afc6b17ea1b87dbceadd3a2cf2520040d51
sha512: 9373c29d79c8977205a6dae07f819ff779f068084b4289286d015a3288006946577f2c508f91e90d6253b8d5a49a0e5d3d215e3f3d3bd62dbbf90206039090ac
ssdeep: 6144:cKQGfCYcMIfX5DOD4K16rf0PL56cSyf4/rdD2PDl88888888bYR3Nwf9ysVufBn:cbmSBO9P96cStQdOOysgfBnnl2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright @ www.download-sponsor.de
InternalName: ocsclient
FileVersion: 1.00
CompanyName: www.download-sponsor.de
Comments: OCSClient v5.0
ProductName: OCSClient
ProductVersion: 1.00
OriginalFilename: ocsclient.exe

PUP.Optional.DownloadSponsor also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebAdware.Downware.2424
FireEyeGeneric.mg.221d2f1f99767ddb
McAfeeArtemis!221D2F1F9976
CylanceUnsafe
VIPREDownloadSponsor (fs)
AegisLabTrojan.Win32.Sponsor.4!c
SangforMalware
K7AntiVirusAdware ( 004bc9fd1 )
K7GWAdware ( 004bc9fd1 )
Cybereasonmalicious.6c51b9
CyrenW32/DownloadSponsor.F.gen!Eldorado
SymantecMobileInsightAppRisk:Generisk
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
RisingPUF.DownloadSponsor!8.222 (TFE:C:9zHwWNt2Y9N)
SophosGeneric PUA EP (PUA)
F-SecurePotentialRisk.PUA/DownloadSponsor.Gen
ZillyaDropper.Agent.Win32.252378
McAfee-GW-EditionBehavesLike.Win32.Fareit.gh
EmsisoftApplication.Downloader (A)
IkarusPUA.DownloadSponsor
AviraPUA/DownloadSponsor.Gen
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftPUA:Win32/DownloadSponsor
GridinsoftPUP.Win32.DownloadSponsor.oa
GDataWin32.Application.OCSClient.B
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Presenoker.C3255775
VBA32Downware.VB.AndreClient
MalwarebytesPUP.Optional.DownloadSponsor
ESET-NOD32a variant of Win32/DownloadSponsor.C potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CB321
TencentMalware.Win32.Gencirc.10bb1ef1
YandexPUA.Downware!N/Q558ZznrA
SentinelOneStatic AI – Malicious PE – Downloader
eGambitUnsafe.AI_Score_99%
FortinetRiskware/DownloadSponsor
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUP.Optional.DownloadSponsor?

PUP.Optional.DownloadSponsor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment