PUA

About “PUP.Optional.Elex” infection

Malware Removal

The PUP.Optional.Elex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Elex virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Creates known PcClient mutex and/or file changes.
  • Anomalous binary characteristics

How to determine PUP.Optional.Elex?


File Info:

name: 7D9352DFFA7215F8E124.mlw
path: /opt/CAPEv2/storage/binaries/3d6c17a7ac4af60191ca29ca53ad87882e9d77cd6f16f8480fe679b2c9949d86
crc32: BDFC5361
md5: 7d9352dffa7215f8e124815170683e06
sha1: d9246b145c3b2650addca0dcf6c7596650c81e9e
sha256: 3d6c17a7ac4af60191ca29ca53ad87882e9d77cd6f16f8480fe679b2c9949d86
sha512: 560f08bce2405a12dd79c271cb16fde89e24497cf6ae40508e40156976062c8ba0c6196089b7f87a742882ca613d0ad2189f1d9b3bb83d100858ec85a7e25d00
ssdeep: 24576:zR6cpYPLURRIWXjmlKGyL7sK9H/TK/b10aT:V6QNNr7Zx/TK/b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3457C5076829176EDE211718EFDAB1F903DA9640B3548EBA3CC0D5E2D30EE22B3575B
sha3_384: 6732c24cb88b6867beec53f45b1b5d31cfc486947b488cd021680ae8eda87712cb40e4bcaf4691f4eb1332f44dd586b9
ep_bytes: e8656d0000e97ffeffffcccccccccccc
timestamp: 2016-08-26 06:44:46

Version Info:

CompanyName: Winziper Pvt Ltd.
FileDescription: Winziper upgrade application
FileVersion: 2.2.28.0
InternalName: wzUpgrade.exe
LegalCopyright: Copyright (c) 2015 Winziper Pvt Ltd. All Rights Reserved.
OriginalFilename: wzUpgrade.exe
ProductName: WinZiper
ProductVersion: 2.2.28.0
Translation: 0x0409 0x04b0

PUP.Optional.Elex also known as:

MicroWorld-eScanGen:Variant.Fugrafa.14735
McAfeeArtemis!7D9352DFFA72
SangforPUP.Win32.ELEX.PIC
K7AntiVirusAdware ( 005192f61 )
K7GWAdware ( 005192f61 )
Cybereasonmalicious.ffa721
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.ELEX.PIC
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Elex.gen
BitDefenderGen:Variant.Fugrafa.14735
SUPERAntiSpywareAdware.Elex/Variant
Ad-AwareGen:Variant.Fugrafa.14735
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Fugrafa.14735
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7d9352dffa7215f8
EmsisoftGen:Variant.Fugrafa.14735 (B)
GDataGen:Variant.Fugrafa.14735
JiangminAdWare.ELEX.cfs
GoogleDetected
AviraADWARE/Elex.gtvdi
Antiy-AVLTrojan/Generic.ASMalwS.4AB4
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Elex.gen
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
VBA32BScope.Adware.Elex
ALYacGen:Variant.Fugrafa.14735
MAXmalware (ai score=85)
MalwarebytesPUP.Optional.Elex
RisingTrojan.Xadupi!8.300C (TFE:5:Nn5TLkVIwzB)
YandexTrojan.GenAsa!k7TmNd13amI
IkarusTrojan.Win32.Xadupi
FortinetRiskware/Elex
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (D)

How to remove PUP.Optional.Elex?

PUP.Optional.Elex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment