PUA

PUP.Optional.DriverPack malicious file

Malware Removal

The PUP.Optional.DriverPack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.DriverPack virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executes obfuscated JavaScript Indicative of CVE 2016-7200 Microsoft Edge Exploit
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
allfont.ru

How to determine PUP.Optional.DriverPack?


File Info:

crc32: 918D7E2E
md5: 8ec3dda4841697c189658236253ec096
name: DriverPack-17-Online_catalog.exe
sha1: 4651acfa14774ea9a1d1160ea73f74578835c06a
sha256: 874f163d3edb662a37f58876fd56a8a429c17b9954eeb1846e277655d8b37b8f
sha512: 956fc9cb17ed2141693780b10e972e4106b43ed94d463f1dd2df0930fbf80d56aa9febc0c345d4eaf8e53327a79ca21285cda10872a2bb01916e568c3d9007f9
ssdeep: 98304:39MRnp/mCWVqstWr8TZWui/axrutKspbv4YCcwi2/esYL25n5neNeIR3wNYhfj:3anxmCmqheWuisutZbWiu1e6N+fj
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

PUP.Optional.DriverPack also known as:

DrWebTrojan.Siggen9.41611
MicroWorld-eScanAdware.GenericKD.33715106
Qihoo-360Win32/Virus.Downloader.0ed
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderAdware.GenericKD.33715106
K7GWAdware ( 005269aa1 )
K7AntiVirusRiskware ( dec003461 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/DriverPack.B potentially unwanted
APEXMalicious
AvastFileRepMalware [PUP]
Kasperskynot-a-virus:HEUR:Downloader.Win32.DriverPack.gen
AlibabaDownloader:Win32/DriverPack.43711fce
Ad-AwareAdware.GenericKD.33715106
EmsisoftAdware.GenericKD.33715106 (B)
TrendMicroTROJ_FRS.VSNTC220
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.8ec3dda4841697c1
SophosGeneric PUA EG (PUA)
IkarusPUA.DriverPack
CyrenW32/Application.PXDS-3617
JiangminTrojan.Banker.CliptoShuffler.o
WebrootW32.Adware.Gen
MAXmalware (ai score=68)
MicrosoftPUA:Win32/Presenoker
Endgamemalicious (high confidence)
ArcabitApplication.DriverPack.H
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.DriverPack.gen
GDataAdware.GenericKD.33715106
AhnLab-V3Win-PUP/DriverPack.Exp
McAfeeArtemis!8EC3DDA48416
MalwarebytesPUP.Optional.DriverPack
TrendMicro-HouseCallTROJ_FRS.VSNTC220
RisingTrojan.DL-Agent/JS!1.A552 (CLASSIC)
YandexTrojan.Hepter.bTxvfp.60
AVGFileRepMalware [PUP]
MaxSecureTrojan.bundler.driverpack.1

How to remove PUP.Optional.DriverPack?

PUP.Optional.DriverPack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment