PUA

PUP.Optional.Soft32Downloader malicious file

Malware Removal

The PUP.Optional.Soft32Downloader is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Soft32Downloader virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine PUP.Optional.Soft32Downloader?


File Info:

name: 75EDEBC0FF3E2ED7E935.mlw
path: /opt/CAPEv2/storage/binaries/65a6396257b9fce6bdd979a15ce0911370a4d1625cc0acf1b90ddf3aa790360f
crc32: F5DFBD53
md5: 75edebc0ff3e2ed7e9355790a2a9ddb3
sha1: 3624b7ffa246de26befd3cbae76b209fe5f14cb0
sha256: 65a6396257b9fce6bdd979a15ce0911370a4d1625cc0acf1b90ddf3aa790360f
sha512: cf2bd69a3a3dc9488bd594d28420abae47afd90139d9602ead3b16cd3a0ddf0371f58050fd105df558b1a47034a312ed9d942ac811c2ed9fcefcc7c34f4b6aea
ssdeep: 6144:Fah+TO0g4oZwLk/MX9LuantRPFi0e9pREOqTZyxPTC62LA9rJTqsBrPkopPqX0R7:FE+O04Zca8RnXFi0e9fAtydT+U9dTfBj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A8412DAF3401C64E52A003B599346A36656E5C9386ECB133F28BD1FFEE5B139E07158
sha3_384: bb8f6d9f473efcdf401ab58ff5871a6a9184eb5dfeb5ba64151630e35300590af9898272566e4dc0bd8ced170417bb01
ep_bytes: 60be00104a008dbe0000f6ff57eb0b90
timestamp: 2010-12-16 04:33:34

Version Info:

CompanyName: Soft32.com
FileDescription: Soft32 Download Manager
FileVersion: 1.0.0
InternalName: Soft32 Download Manager
LegalCopyright: © Soft32.com
OriginalFilename: soft32-downloader-1.0.0.0.exe
ProductName: Soft32 Download Manager
ProductVersion: 1.0.0
Translation: 0x0409 0x04e4

PUP.Optional.Soft32Downloader also known as:

LionicAdware.Win32.Generic.lzSD
FireEyeGeneric.mg.75edebc0ff3e2ed7
CAT-QuickHealDownldr.GenericCS.S18042
K7AntiVirusRiskware ( 0040eff71 )
AlibabaDownloader:Win32/FakeAV.978c6480
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fa246d
VirITWorm.Win32.AutoRun.MB
CyrenW32/S-170e5e65!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ClamAVWin.Virus.Sality-6832507-0
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
NANO-AntivirusRiskware.Win32.Adw.dwxwpx
DrWebAdware.Downware.8
TrendMicroTROJ_GEN.R002C0OED22
EmsisoftApplication.Downloader (A)
IkarusTrojan.Win32.FakeAV
JiangminDownloader.Generic.da
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.408A
ViRobotAdware.Wacatac.379673
CynetMalicious (score: 100)
VBA32Trojan.FakeAV
MalwarebytesPUP.Optional.Soft32Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0OED22
RisingDownloader.Generic!8.141 (CLOUD)
YandexPUA.Downware!hBK3b+m5SGo
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Trick

How to remove PUP.Optional.Soft32Downloader?

PUP.Optional.Soft32Downloader removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment