Malware

About “Win32/DownloadSponsor.A potentially unwanted” infection

Malware Removal

The Win32/DownloadSponsor.A potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DownloadSponsor.A potentially unwanted virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Anomalous binary characteristics

Related domains:

bin.download-sponsor.de

How to determine Win32/DownloadSponsor.A potentially unwanted?


File Info:

crc32: 039500AF
md5: 9c6498bdc41885d0b71c2a633ac20767
name: 9C6498BDC41885D0B71C2A633AC20767.mlw
sha1: ba373911a26badc4f69d4c7241a6db92393eefc3
sha256: 23c3db2d237a69aab9a9e476aac29cc5cfc58707dba034d8cd0459e693c631d0
sha512: e5ae42158f0cc2aeb4b18d8ca8a6ccc209c7d6b434b72b2d0abb06efe6b469b544e77f50bdb3ded7ceb302cdab87fb92a54a251419abbbde65aff4fc64d904e0
ssdeep: 6144:QKWplAfC0Jk1281yDzqH4EXciV/5+OUi/foysVufBn597NX2:Q7Af9JkE81mSP1AziYysgfBnnl2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright @ www.download-sponsor.de
InternalName: ocsclient
FileVersion: 1.00
CompanyName: www.download-sponsor.de
Comments: OCSClient v5.0
ProductName: OCSClient
ProductVersion: 1.00
OriginalFilename: ocsclient.exe

Win32/DownloadSponsor.A potentially unwanted also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 004bc9fd1 )
Elasticmalicious (high confidence)
DrWebAdware.Downware.2252
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaDownloader.DownloadSponsor.Win32.144
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 004bc9fd1 )
Cybereasonmalicious.1a26ba
CyrenW32/DownloadSponsor.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DownloadSponsor.A potentially unwanted
APEXMalicious
AvastFileRepMetagen [PUP]
ClamAVWin.Dropper.LokiBot-6991918-0
Kasperskynot-a-virus:Downloader.Win32.DownloadSponsor.ll
NANO-AntivirusTrojan.Win32.DownloadSponsor.eziyuo
SophosGeneric PUA LK (PUA)
ComodoApplicUnwnt@#1ixprmmhz9h80
VIPREDownloadSponsor (fs)
McAfee-GW-EditionBehavesLike.Win32.BadFile.hh
FireEyeGeneric.mg.9c6498bdc41885d0
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.DownloadSponsor.f
AviraPUA/DownloadSponsor.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywarePUP.DownloadSponsor/Variant
GDataWin32.Application.OCSClient.B
McAfeeArtemis!9C6498BDC418
MAXmalware (ai score=97)
VBA32Downware.VB.AndreClient
MalwarebytesPUP.Optional.DownloadSponsor
YandexRiskware.Agent!xe+onkc2LMo
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DownloadSponsor
AVGFileRepMetagen [PUP]
Paloaltogeneric.ml

How to remove Win32/DownloadSponsor.A potentially unwanted?

Win32/DownloadSponsor.A potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment