PUA

Win32:Downloader-UED [PUP] removal

Malware Removal

The Win32:Downloader-UED [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Downloader-UED [PUP] virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:Downloader-UED [PUP]?


File Info:

name: 031C6481FE4453BEE9A9.mlw
path: /opt/CAPEv2/storage/binaries/16b35e5c99018315f73bc76445aaf8b58fe1274c31c2ef5e7a17f907590cfd81
crc32: 7D150686
md5: 031c6481fe4453bee9a973858cef48b6
sha1: 612b7cd199b63e614cdbfff677ad798ab601fa19
sha256: 16b35e5c99018315f73bc76445aaf8b58fe1274c31c2ef5e7a17f907590cfd81
sha512: e076b98dbaaa39c301c2d8fbb24bf026eb654ff5c50eee3d3d3d3463e37d720275fa608980bca28fe1901571ee4bb6bf1f48b123b062cbabaf38a86612489b64
ssdeep: 1536:b07XLNylYuCBdpsfMu4Dx+f6ib4Fgvssfvy3YxI:w7XLguuou41+iib4Fgvs3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14963D00F738B94A2D40E28B1568BD8A1A725FF2C54D66FFB8302B663B6BC3475634351
sha3_384: ca89b849210a0bc9fb2e47ce468f027fede5c0e67e7624ab394fd303a50a84afa2ce8a2c7998c389528e7afa43e5a54f
ep_bytes: 5589e583ec18c7042402000000ff1558
timestamp: 2013-12-06 22:16:07

Version Info:

0: [No Data]

Win32:Downloader-UED [PUP] also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Application.LoadMoney.1
ClamAVWin.Trojan.Loadmoney-11778
FireEyeGeneric.mg.031c6481fe4453be
CAT-QuickHealTrojanDownloader.Ogimant.A7
McAfeePUP-FFL
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Application.LoadMoney.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f53f1 )
AlibabaTrojan:Win32/Dorv.e062bff8
K7GWTrojan ( 005690671 )
Cybereasonmalicious.1fe445
BaiduWin32.Trojan.Kryptik.dl
CyrenW32/LoadMoney.K.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.CGBF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.LMN.apm
BitDefenderGen:Application.LoadMoney.1
NANO-AntivirusTrojan.Win32.LMN.eybbqx
SUPERAntiSpywareTrojan.Agent/Gen-LoadMoney
AvastWin32:Downloader-UED [PUP]
TencentMalware.Win32.Gencirc.10b2265e
Ad-AwareGen:Application.LoadMoney.1
SophosTroj/LdMon-A
F-SecurePotentialRisk.PUA/LoadMoney.Gen7
DrWebTrojan.LoadMoney.1
ZillyaDownloader.LMNGen.Win32.8
TrendMicroTROJ_OGIMANT.SMB
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.kc
Trapminemalicious.high.ml.score
EmsisoftGen:Application.LoadMoney.1 (B)
IkarusTrojan.Win32.Spy
JiangminTrojan/Generic.atwqf
WebrootW32.Downloader.Gen
AviraPUA/LoadMoney.Gen7
MAXmalware (ai score=100)
Antiy-AVLRiskWare[Downloader]/Win32.LMN
MicrosoftPUAAdvertising:Win32/LoadMoney
XcitiumTrojWare.Win32.Kryptik.BWTI@58g70v
ArcabitApplication.LoadMoney.1
GDataGen:Application.LoadMoney.1
GoogleDetected
AhnLab-V3PUP/Win32.LoadMoney.R228134
VBA32BScope.Downloader.LMN
ALYacGen:Application.LoadMoney.1
Cylanceunsafe
TrendMicro-HouseCallTROJ_OGIMANT.SMB
RisingTrojan.Agent!1.6956 (CLASSIC)
YandexTrojan.GenAsa!KEJ6wTzsXkU
SentinelOneStatic AI – Suspicious PE
MaxSecurenot-a-virus:Downloader.LMN.a
FortinetW32/Generic.AC.6F6F!tr
AVGWin32:Downloader-UED [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:Downloader-UED [PUP]?

Win32:Downloader-UED [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment