Categories: PUA

PUP.Optional.ThrDownloader information

The PUP.Optional.ThrDownloader is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.ThrDownloader virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine PUP.Optional.ThrDownloader?


File Info:

name: F42D585AA2FCF48A604F.mlwpath: /opt/CAPEv2/storage/binaries/51e55afee37f01c179940fad63c7828d4b87c98810bfe8732ca339f21ef9ab98crc32: 156B3E5Amd5: f42d585aa2fcf48a604f0c94c2b81b4bsha1: 9bc82872069940c95e90a542cab3202e63288755sha256: 51e55afee37f01c179940fad63c7828d4b87c98810bfe8732ca339f21ef9ab98sha512: 98b75a6b45161a0b78eae3d31ff3551724cc8bd563ec3af2cadb2e8c4873c64a360990d4f8b54f51bd62ab11ad1d614645667b135df85358e5cf95081b9ac63bssdeep: 12288:FYAkF7EEVpldmREl+t5N7LF7WD9RWiJ0REINuLqRc5JAHqy/qMcLEi:FYAkN1Qt55F7WJRWirINejTAqMFtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T173C48D62B6E0C43BD0621B745CEFA2B2583DBF142E244D4777E41F8C5F756903A1A2ABsha3_384: 7f98bb68e2cad044211de5e3839a5f04f3ab23865e3ca35dcbf4e3aa8d8a8fe073dc9a4aba92d8eb32ffcf5b455ede01ep_bytes: eb1066623a432b2b484f4f4b90e98c80timestamp: 2015-02-23 03:14:51

Version Info:

0: [No Data]

PUP.Optional.ThrDownloader also known as:

Lionic Trojan.Win32.Foreign.j!c
DrWeb Trojan.Vittalia.150
MicroWorld-eScan Gen:Variant.Adware.Graftor.182541
FireEye Generic.mg.f42d585aa2fcf48a
McAfee PUP-XAE-TO
Cylance Unsafe
Zillya Trojan.Black.Win32.31125
K7AntiVirus Adware ( 004c53de1 )
Alibaba Ransom:Win32/Foreign.82a2b5ae
K7GW Adware ( 004c53de1 )
Cybereason malicious.aa2fcf
VirIT Trojan.Win32.Vittalia.FU
Symantec SMG.Heur!gen
ESET-NOD32 a variant of Win32/Adware.PEerMarket.G
TrendMicro-HouseCall Ransom_Foreign.R002C0OL421
Paloalto generic.ml
ClamAV Win.Trojan.Agent-1277615
Kaspersky HEUR:Trojan-Ransom.Win32.Foreign.gen
BitDefender Gen:Variant.Adware.Graftor.182541
NANO-Antivirus Trojan.Win32.Vittalia.eamujl
Avast FileRepMalware
Tencent Malware.Win32.Gencirc.10b1de4b
Ad-Aware Gen:Variant.Adware.Graftor.182541
Sophos Generic PUA JL (PUA)
TrendMicro Ransom_Foreign.R002C0OL421
McAfee-GW-Edition PUP-XAE-TO
Emsisoft Gen:Variant.Adware.Graftor.182541 (B)
GData Gen:Variant.Adware.Graftor.182541
Jiangmin Trojan/Generic.bhtaj
Avira HEUR/AGEN.1102407
MAX malware (ai score=60)
Gridinsoft Ransom.Win32.Sabsik.sa
ViRobot Trojan.Win32.Z.Vittalia.595456
Microsoft Trojan:Win32/Sabsik.FL.B!ml
AhnLab-V3 PUP/Win32.Downware.R158717
VBA32 Trojan.Reconyc
ALYac Gen:Variant.Adware.Graftor.182541
Malwarebytes PUP.Optional.ThrDownloader
APEX Malicious
Rising Trojan.Generic@ML.100 (RDML:Onu99KfkWuI8py59KnzGIw)
Ikarus Trojan-Dropper.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/PEerMarket
AVG FileRepMalware
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_100% (D)

How to remove PUP.Optional.ThrDownloader?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Malware.AI.2972915474 malicious file

The Malware.AI.2972915474 is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Win32/Autoit.OPN information

The Win32/Autoit.OPN is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Malware.AI.3788326785 removal

The Malware.AI.3788326785 is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

What is “Trojan.Generic.35619263”?

The Trojan.Generic.35619263 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Dacic.1A7FA519.A.F34D6DE8 removal instruction

The Generic.Dacic.1A7FA519.A.F34D6DE8 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “Babar.143901”?

The Babar.143901 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago