Malware

Win32/DownloadGuide.D potentially unwanted removal guide

Malware Removal

The Win32/DownloadGuide.D potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DownloadGuide.D potentially unwanted virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

dlg-configs.buzzrin.de
dlg-messages.buzzrin.de
az687722.vo.msecnd.net

How to determine Win32/DownloadGuide.D potentially unwanted?


File Info:

crc32: 3CEA97A3
md5: f61209b752a6d6b2e2694d53bb4b7a78
name: download-audiograbber.exe
sha1: 713bbb92dd9c453479912f8014863a759de9c97e
sha256: 3bd41152a9ad825c3071b70a3936e3c3fb6a7af1524d8fba7570ca586016dd9b
sha512: e560b1d7dbd4ea3dfa76f5926ffc7c08490314f3b2fa394808382981cf2c16818b9419b9df1541232a8aeda5e89060d346defa55dd4f6b841c36650811d282a4
ssdeep: 12288:U4fmuV/2SlI1MCAHab5I0WozQsmknY87Z1EPclMkc9A7Z2NS:U42DMCA6b5fWQmknY87LEPcl9nlR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 3.1.0.201

Win32/DownloadGuide.D potentially unwanted also known as:

MicroWorld-eScanApplication.Bundler.DownloadGuide.KE
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePUP-FXK
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderApplication.Bundler.DownloadGuide.KE
TrendMicroTROJ_GEN.R01FC0PB420
F-ProtW32/S-58b25de1!Eldorado
AvastWin32:UnwantedSig [PUP]
ClamAVWin.Malware.Downloadguide-6803841-0
GDataWin32.Application.DownloadGuide.T
Kasperskynot-a-virus:HEUR:Downloader.Win32.DownloaderGuide.gen
NANO-AntivirusRiskware.Win32.Covus.fkfkjs
RisingAdware.DownloadGuide!1.A1DB (RDMK:cmRtazqlpYKyzNMKOGhjAqrKjcET)
Endgamemalicious (high confidence)
EmsisoftApplication.Bundler.DownloadGuide.KE (B)
ComodoApplication.Win32.DownloadGuide.A@7y5gwx
DrWebAdware.ClickMeIn.9588
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.hh
FireEyeGeneric.mg.f61209b752a6d6b2
SophosDownloadGuide (PUA)
IkarusPUA.DownloadGuide
CyrenW32/S-58b25de1!Eldorado
JiangminDownloader.DownloaderGuide.aqk
WebrootPua.Freemium
eGambitUnsafe.AI_Score_100%
Antiy-AVLGrayWare[AdWare]/Win32.DownloadGuide.dd
MicrosoftPUA:Win32/Puwaders.B!ml
ArcabitApplication.Bundler.DownloadGuide.KE
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.DownloaderGuide.gen
AhnLab-V3PUP/Win32.DownloadGuide.R245289
VBA32Downloader.DownloaderGuide
MAXmalware (ai score=77)
Ad-AwareApplication.Bundler.DownloadGuide.KE
MalwarebytesAdware.Downloader
ESET-NOD32a variant of Win32/DownloadGuide.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FC0PB420
TencentMalware.Win32.Gencirc.10b0a5b4
YandexPUA.Downloader!
SentinelOneDFI – Malicious PE
MaxSecureTrojan.bundler.downloadguide.kee_169373
FortinetRiskware/DownloaderGuide
AVGWin32:UnwantedSig [PUP]
Cybereasonmalicious.752a6d

How to remove Win32/DownloadGuide.D potentially unwanted?

Win32/DownloadGuide.D potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment