PUA

PUP.Optional.ThrDownloader information

Malware Removal

The PUP.Optional.ThrDownloader is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.ThrDownloader virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine PUP.Optional.ThrDownloader?


File Info:

name: F42D585AA2FCF48A604F.mlw
path: /opt/CAPEv2/storage/binaries/51e55afee37f01c179940fad63c7828d4b87c98810bfe8732ca339f21ef9ab98
crc32: 156B3E5A
md5: f42d585aa2fcf48a604f0c94c2b81b4b
sha1: 9bc82872069940c95e90a542cab3202e63288755
sha256: 51e55afee37f01c179940fad63c7828d4b87c98810bfe8732ca339f21ef9ab98
sha512: 98b75a6b45161a0b78eae3d31ff3551724cc8bd563ec3af2cadb2e8c4873c64a360990d4f8b54f51bd62ab11ad1d614645667b135df85358e5cf95081b9ac63b
ssdeep: 12288:FYAkF7EEVpldmREl+t5N7LF7WD9RWiJ0REINuLqRc5JAHqy/qMcLEi:FYAkN1Qt55F7WJRWirINejTAqMF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173C48D62B6E0C43BD0621B745CEFA2B2583DBF142E244D4777E41F8C5F756903A1A2AB
sha3_384: 7f98bb68e2cad044211de5e3839a5f04f3ab23865e3ca35dcbf4e3aa8d8a8fe073dc9a4aba92d8eb32ffcf5b455ede01
ep_bytes: eb1066623a432b2b484f4f4b90e98c80
timestamp: 2015-02-23 03:14:51

Version Info:

0: [No Data]

PUP.Optional.ThrDownloader also known as:

LionicTrojan.Win32.Foreign.j!c
DrWebTrojan.Vittalia.150
MicroWorld-eScanGen:Variant.Adware.Graftor.182541
FireEyeGeneric.mg.f42d585aa2fcf48a
McAfeePUP-XAE-TO
CylanceUnsafe
ZillyaTrojan.Black.Win32.31125
K7AntiVirusAdware ( 004c53de1 )
AlibabaRansom:Win32/Foreign.82a2b5ae
K7GWAdware ( 004c53de1 )
Cybereasonmalicious.aa2fcf
VirITTrojan.Win32.Vittalia.FU
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Adware.PEerMarket.G
TrendMicro-HouseCallRansom_Foreign.R002C0OL421
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1277615
KasperskyHEUR:Trojan-Ransom.Win32.Foreign.gen
BitDefenderGen:Variant.Adware.Graftor.182541
NANO-AntivirusTrojan.Win32.Vittalia.eamujl
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10b1de4b
Ad-AwareGen:Variant.Adware.Graftor.182541
SophosGeneric PUA JL (PUA)
TrendMicroRansom_Foreign.R002C0OL421
McAfee-GW-EditionPUP-XAE-TO
EmsisoftGen:Variant.Adware.Graftor.182541 (B)
GDataGen:Variant.Adware.Graftor.182541
JiangminTrojan/Generic.bhtaj
AviraHEUR/AGEN.1102407
MAXmalware (ai score=60)
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Vittalia.595456
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3PUP/Win32.Downware.R158717
VBA32Trojan.Reconyc
ALYacGen:Variant.Adware.Graftor.182541
MalwarebytesPUP.Optional.ThrDownloader
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:Onu99KfkWuI8py59KnzGIw)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/PEerMarket
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUP.Optional.ThrDownloader?

PUP.Optional.ThrDownloader removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment