PUA

PUP.Optional.AdOffer removal instruction

Malware Removal

The PUP.Optional.AdOffer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.AdOffer virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • Authenticode signature is invalid

How to determine PUP.Optional.AdOffer?


File Info:

name: D43E12C4C5D319BADE80.mlw
path: /opt/CAPEv2/storage/binaries/7aaaf196b365bd902dd20d3a118fb341ee322dc22b622e5ca1089da89aaada1d
crc32: 721BD909
md5: d43e12c4c5d319bade804d984fc058e5
sha1: e844b835dac8af1070fd1134e5a9bae614cbcd14
sha256: 7aaaf196b365bd902dd20d3a118fb341ee322dc22b622e5ca1089da89aaada1d
sha512: 8f41416f3fb71dd40883b72f58d9b646df26932a73a8f29831bbe3110a0c6e244bb189a9974c6c36995d0e4ebfb77f187469d28570dfdb9aa1a2b743aac23c96
ssdeep: 1536:juXtm/kOdwbVl6iuEg1gBkfW+sfa3n8lkvM4hAO+odN+zQU:iWULuE0g3+JnHhAadNcr
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1ECA34C107650C035E4EB04BA8EFE577C973E6921476954C3A3981EBE5F72AE23E3121B
sha3_384: c6d70b846fb31c42970a9757d5c1cf96d0c9d8d6de4d376448a6c7fdd861935a865526cc46eaa325dc2b2dec98d7c0ef
ep_bytes: 8bff558bec837d0c017505e8cb2a0000
timestamp: 2014-10-28 10:27:10

Version Info:

FileVersion: 1.3.0.0
LegalCopyright: Copyright (C) 2014
ProductVersion: 1.3.0.0
Translation: 0x0009 0x04b0

PUP.Optional.AdOffer also known as:

LionicAdware.Win32.Bundler.2!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanApplication.Bundler.TF
FireEyeApplication.Bundler.TF
ALYacApplication.Bundler.TF
Cylanceunsafe
CrowdStrikewin/grayware_confidence_60% (W)
AlibabaAdWare:Win32/Somoto.dbff8c35
VirITAdware.Win32.Somoto.FD
ESET-NOD32Win32/Somoto.T potentially unwanted
Kasperskynot-a-virus:AdWare.Win32.Agent.iraa
BitDefenderApplication.Bundler.TF
NANO-AntivirusRiskware.Win32.Agent.dtnfhl
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Agent.Wozm
EmsisoftApplication.Bundler.TF (B)
DrWebAdware.Somoto.133
VIPREApplication.Bundler.TF
JiangminAdware/Agent.rdh
Antiy-AVLGrayWare[AdWare]/Win32.Agent
ArcabitApplication.Bundler.TF
ViRobotAdware.Agent.102912.AD
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.iraa
GDataApplication.Bundler.TF
GoogleDetected
MAXmalware (ai score=100)
VBA32AdWare.Agent
MalwarebytesPUP.Optional.AdOffer
TrendMicro-HouseCallADW_TOMOS
RisingMalware.Undefined!8.C (TFE:5:KQSB2bN3uoD)
YandexTrojan.GenAsa!yoeFTxBt944
FortinetAdware/Somoto_BetterInstaller
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove PUP.Optional.AdOffer?

PUP.Optional.AdOffer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment