PUA

PUP.Optional.CRaccoon information

Malware Removal

The PUP.Optional.CRaccoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.CRaccoon virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed analysis tools by a known file location
  • Harvests cookies for information gathering

How to determine PUP.Optional.CRaccoon?


File Info:

name: F2944A6942BAED06F517.mlw
path: /opt/CAPEv2/storage/binaries/3a80d64af2229b01ab2ff9e8e749a0daae743a25c9a094dc063b8c5a37c7a5b1
crc32: 2C35B678
md5: f2944a6942baed06f51777105b7bd8b6
sha1: f66fffb9ed4ca4e987c2422bc83a4105cdf43b52
sha256: 3a80d64af2229b01ab2ff9e8e749a0daae743a25c9a094dc063b8c5a37c7a5b1
sha512: 287735af7a5388eb5084ae4a4488d570591f28476c44abd36bfaac3f2fa96ddc468eddfb1fb2462f1b6581537c207834b3f39a4a651a51766b6f69be2ea2284b
ssdeep: 98304:1asDx80C0FweqtqbfiPO7T9XcrQbrF5vFNsGXwWMcy5M:1NV8B037i27T9Xbbp5voG6cn
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1B216E0067A98E9E9D0769238A7735BC1E379B8050370D9DF0383476EDF1A1A27E39790
sha3_384: d367b301b88b90f1e2fa51a0ec654a01d42e3ce85adda220e4598ecc529b630c358ec046d521ff3e950a4704620f22bf
ep_bytes: 4883ec28e81b0800004883c428e97afe
timestamp: 2021-07-26 13:04:38

Version Info:

0: [No Data]

PUP.Optional.CRaccoon also known as:

LionicAdware.Win64.Craccoon.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3019425
McAfeeArtemis!F2944A6942BA
CylanceUnsafe
ZillyaAdware.Craccoon.Win64.7
SangforAdware.Win32.Craccoon.gen
K7AntiVirusAdware ( 0057fe7e1 )
AlibabaAdWare:Win64/Craccoon.d406ff54
K7GWAdware ( 0057fe7e1 )
CyrenW64/Trojan.SYRE-6871
SymantecPUA.Gen.2
ESET-NOD32a variant of Win64/Adware.SecureDuck.A
TrendMicro-HouseCallTROJ_GEN.R023H07H121
Kasperskynot-a-virus:HEUR:AdWare.Win64.Craccoon.gen
BitDefenderApplication.Generic.3019425
AvastWin64:Adware-gen [Adw]
Ad-AwareApplication.Generic.3019425
EmsisoftApplication.Generic.3019425 (B)
DrWebTrojan.MulDrop18.44817
McAfee-GW-EditionArtemis
FireEyeApplication.Generic.3019425
SophosGeneric PUA PG (PUA)
GDataApplication.Generic.3019425
JiangminAdWare.Craccoon.b
MAXmalware (ai score=70)
ArcabitApplication.Generic.D2E12A1
MicrosoftProgram:Win32/Uwamson.A!ml
VBA32Adware.Win64.Craccoon
ALYacApplication.Generic.3019425
MalwarebytesPUP.Optional.CRaccoon
MaxSecureTrojan.Malware.120228894.susgen
FortinetAdware/Craccoon
AVGWin64:Adware-gen [Adw]
PandaPUP/Adware

How to remove PUP.Optional.CRaccoon?

PUP.Optional.CRaccoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment