PUA

Win32:Downloader-UFN [PUP] information

Malware Removal

The Win32:Downloader-UFN [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Downloader-UFN [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Downloader-UFN [PUP]?


File Info:

name: 2225D34B305FB21D7BCF.mlw
path: /opt/CAPEv2/storage/binaries/a4dafd18987cb7edb350dba91c5d8ac23ccfc7bf1e9e3f7c610a38dee4733b65
crc32: C221CD06
md5: 2225d34b305fb21d7bcfdbacb724095e
sha1: 92a93dc9368e106dce4adb0e145786dc92ccbc2c
sha256: a4dafd18987cb7edb350dba91c5d8ac23ccfc7bf1e9e3f7c610a38dee4733b65
sha512: 8d04b044cd52a47a9095699ffcdb3d20308cb5944352fcb247987ef3f09390a4be4b23584c2b91faa385b81df782e70e9c56442d906804d7007ba37a7b83e4a0
ssdeep: 1536:tnrWdE7rZas+MWpyqAbXyleFKkaTZ9R/rjf90uXoQI+RZ7J0YRMv0PKC/Oq2r:trWga3p1AzyQreZPrjfiuX6iaYRMUKSm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18783D08697505CD2FAF849355867DD541AB8FF8DB7C21A37829BA23B7CF23A0410781E
sha3_384: 88e81b4086401a89a9c2070c0ca2ddcb3930c31b0cb9511a1169750373005b7eccf67bf977427e9c035c49dcfecf6bc1
ep_bytes: 60be150042008dbeeb0ffeff5783cdff
timestamp: 2013-09-16 18:42:11

Version Info:

0: [No Data]

Win32:Downloader-UFN [PUP] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lW9K
tehtrisGeneric.Malware
MicroWorld-eScanGen:Application.LoadMoney.1
FireEyeGeneric.mg.2225d34b305fb21d
CAT-QuickHealPUA.LLCMail.DC7
ALYacGen:Application.LoadMoney.1
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Application.LoadMoney.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f53f1 )
AlibabaAdWare:Win32/Kryptik.f5e2a939
K7GWTrojan ( 0040f53f1 )
Cybereasonmalicious.b305fb
CyrenW32/LoadMoney.EI.gen!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.CGBF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Loadmoney-11738
Kasperskynot-a-virus:AdWare.Win32.LMN.apm
BitDefenderGen:Application.LoadMoney.1
NANO-AntivirusTrojan.Win32.LoadMoney.dnqdsy
SUPERAntiSpywareAdware.LoadMoney/Variant
AvastWin32:Downloader-UFN [PUP]
TencentAdware.Win32.Lmn.yq
EmsisoftGen:Application.LoadMoney.1 (B)
BaiduWin32.Trojan.Kryptik.dl
F-SecurePotentialRisk.PUA/LoadMoney.Gen
DrWebTrojan.LoadMoney.1
ZillyaTrojan.Kryptik.Win32.3009617
TrendMicroTROJ_GEN.R002C0OB523
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mc
Trapminemalicious.moderate.ml.score
SophosTroj/LdMon-A
IkarusPUA.Gen
GDataGen:Application.LoadMoney.1
JiangminTrojan/Generic.atwqf
Webroot
GoogleDetected
AviraPUA/LoadMoney.Gen
Antiy-AVLRiskWare[Downloader]/Win32.LoadMoney.aa
XcitiumTrojWare.Win32.Kryptik.BWTI@58g70v
ArcabitApplication.LoadMoney.1
ZoneAlarmnot-a-virus:AdWare.Win32.LMN.apm
MicrosoftPUAAdvertising:Win32/LoadMoney
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.LoadMoney.R228135
McAfeeArtemis!2225D34B305F
MAXmalware (ai score=79)
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0OB523
RisingDownloader.Small!1.65D6 (CLOUD)
YandexTrojan.GenAsa!b4NXpdd5TH4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CGBF!tr
AVGWin32:Downloader-UFN [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32:Downloader-UFN [PUP]?

Win32:Downloader-UFN [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment