PUA

What is “PUP.Optional.VeryFast.DDS”?

Malware Removal

The PUP.Optional.VeryFast.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.VeryFast.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Accessed credential storage registry keys
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUP.Optional.VeryFast.DDS?


File Info:

name: 8E8EE08E78073E23C44F.mlw
path: /opt/CAPEv2/storage/binaries/567885716ef479d6f2397d450259423bfa29130db3c18e100c08a6b6aa714586
crc32: 20D3160C
md5: 8e8ee08e78073e23c44fdd57c38189d1
sha1: 960bebd5b60e56721a6f9dad75f2ec975695ea96
sha256: 567885716ef479d6f2397d450259423bfa29130db3c18e100c08a6b6aa714586
sha512: 01e74476ebcb7ffcc99a5c4d34cd1a59f3b4e31dd903f522e5190640aaa9558b070d429af11e2558c4a55da6f3084e7c7b3c471852dbc0fde51994375d30a1aa
ssdeep: 1536:P/T2X/jN2vxZz0DTHUpou08xuIwisaKLDeO2y4a/SOxE+1zyYCDtpXOrQ78mxvhC:PbG7N2kDTHUpou0sdt8J/bPzy5n+cp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17EA3AE60B350C466F4A3CB301565963A5A79AC21F5904B4F3FE06A4869EE3F19F2E3E1
sha3_384: 46fa63013c373df17044fea61ba079ec59184e6c6c95687f2b4219d97d13143b5e3b6cfc08b25e85ee7b2a472977475e
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

0: [No Data]

PUP.Optional.VeryFast.DDS also known as:

BkavW32.Common.4781523F
MalwarebytesPUP.Optional.VeryFast.DDS
ZillyaAdware.PCAppStore.Win32.417
SangforAdware.Win32.Veryfast.Vyrl
K7GWAdware ( 005b19f41 )
K7AntiVirusAdware ( 005b19f41 )
SymantecPUA.Gen.2
ESET-NOD32Win32/Adware.VeryFast.M
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.PCAppStore.gen
AvastNSIS:AdwareX-gen [Adw]
TencentWin32.Trojan.FalseSign.Wwhl
F-SecureAdware.ADWARE/Redcap.wktfb
DrWebProgram.Unwanted.5478
SophosGeneric Reputation PUA (PUA)
AviraADWARE/Redcap.wktfb
Antiy-AVLGrayWare[AdWare]/Win32.PCAppStore.gen
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.PCAppStore.gen
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07BJ24
FortinetRiskware/VeryFast
AVGNSIS:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove PUP.Optional.VeryFast.DDS?

PUP.Optional.VeryFast.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment