PUA

About “PUP.Optional.Kuauzip.DDS” infection

Malware Removal

The PUP.Optional.Kuauzip.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Kuauzip.DDS virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.universal101.com

How to determine PUP.Optional.Kuauzip.DDS?


File Info:

crc32: 6676A2F4
md5: f82be596ffdf0c0beede8aa551aaa26b
name: F82BE596FFDF0C0BEEDE8AA551AAA26B.mlw
sha1: 56e9de4f4b98ac7642c67fdcf4aae040781261da
sha256: 69d89bc2fb48f7c1eab0c426abb16722855c59dab5983515645483920c65a05b
sha512: b35ffef51ebc0d774b8e231c40b300e497a435ad0d774dbe430ba52c7732cf89696cf67a308d8af90f21f666764854f766a0ee4183064a3c1af0238a54922e49
ssdeep: 49152:67N1ahCD0V7N1ahCZ0V7N1ahCy0V7N1ahChd0:6727M7f7h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUP.Optional.Kuauzip.DDS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35681909
FireEyeGeneric.mg.f82be596ffdf0c0b
CAT-QuickHealWorm.Nuj.B8
ALYacTrojan.GenericKD.35681909
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 0001b7311 )
BitDefenderTrojan.GenericKD.35681909
K7GWTrojan-Downloader ( 0001b7311 )
Cybereasonmalicious.6ffdf0
CyrenW32/Oberal.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Small-MHA [Trj]
ClamAVWin.Malware.Alkt-6915258-0
KasperskyTrojan.Win32.Small.xxd
NANO-AntivirusTrojan.Win32.Small.cnwqmt
ViRobotTrojan.Win32.Banker.741376.C
RisingTrojan.Oberal!1.BDEF (CLASSIC)
Ad-AwareTrojan.GenericKD.35681909
TACHYONTrojan/W32.DP-Downloader.Zen
EmsisoftTrojan.GenericKD.35681909 (B)
ComodoTrojWare.Win32.Small.~QW@gohe
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.LowZones.1991
TrendMicroTROJ_FAKEAV.SMNA
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosML/PE-A + Mal/QLowZ-A
IkarusTrojan-Banker.Win32.Banker
JiangminTrojanSpy.Banker.rpg
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Small.xxd
MicrosoftPUA:Win32/KuaiZip
ArcabitTrojan.Generic.D2207675
ZoneAlarmTrojan.Win32.Small.xxd
GDataWin32.Trojan.FakeAV.Q
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R73886
Acronissuspicious
McAfeegeneric!bg.yb
MAXmalware (ai score=80)
VBA32TScope.Trojan.Delf
MalwarebytesPUP.Optional.Kuauzip.DDS
PandaTrj/Banker.FWD
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.VA
TrendMicro-HouseCallTROJ_FAKEAV.SMNA
TencentTrojan.Win32.Small.b
YandexTrojan.GenAsa!RZ0bt4DpWOE
SentinelOneStatic AI – Malicious PE – Spyware
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Banker.ACSI!tr
BitDefenderThetaAI:Packer.14C16B3A19
AVGWin32:Small-MHA [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360QVM41.1.Malware.Gen

How to remove PUP.Optional.Kuauzip.DDS?

PUP.Optional.Kuauzip.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment