PUA

PUP.Optional.Eyoorun information

Malware Removal

The PUP.Optional.Eyoorun is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Eyoorun virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUP.Optional.Eyoorun?


File Info:

name: 2604D1B7420AB21B8289.mlw
path: /opt/CAPEv2/storage/binaries/bb8d7e6303f2b3809f674e8fa6526a14ef3c0d2a6c8732dae5ff96368d46a576
crc32: 0DE009ED
md5: 2604d1b7420ab21b8289cf0cf409205a
sha1: de0f2b98986704482ec7a741c8a319423494db63
sha256: bb8d7e6303f2b3809f674e8fa6526a14ef3c0d2a6c8732dae5ff96368d46a576
sha512: 40c71c0da1fa68f8df133a5910cf0ec3704fb334725c3e5cbba5fd542f5f66a6fed30d3df777330dceb191e531f0220bfc50a2317ff07eb719c7ce9492998ad5
ssdeep: 49152:g9KFeMN0YAaVo8oP3KpuZj3QcG2jGnYALtV77q77XMx77j77NtR7kz7T77Ob787X:g0FeHT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBA56C46B7A18572C45BC27889B7461AE672BC02072187C773D9BB6E3F333D05A3A761
sha3_384: 324648129f85bd223e7de0947a5b25712db3ebb4acf4015c581143859d95bcbe7f24b5c5f0ded0edbcaf2a23fcfea3bd
ep_bytes: e891b50000e940feffffcccccccccccc
timestamp: 2023-06-29 03:14:00

Version Info:

FileVersion: 1, 0, 1, 6
ProductVersion: 1, 0, 1, 6
Translation: 0x0804 0x04b0

PUP.Optional.Eyoorun also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Doina.51920
FireEyeGeneric.mg.2604d1b7420ab21b
SkyhighBehavesLike.Win32.Generic.vm
McAfeeArtemis!2604D1B7420A
Cylanceunsafe
VIPREGen:Variant.Doina.51920
Cybereasonmalicious.898670
ArcabitTrojan.Doina.DCAD0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
CynetMalicious (score: 99)
APEXMalicious
BitDefenderGen:Variant.Doina.51920
AvastWin64:TrojanX-gen [Trj]
EmsisoftGen:Variant.Doina.51920 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.MulDrop22.54541
ZillyaTrojan.VMProtect.Win32.85085
Trapminesuspicious.low.ml.score
IkarusTrojan.Crypt
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Doina.51920
GoogleDetected
AhnLab-V3Trojan/Win.Trojan-gen.R601619
BitDefenderThetaGen:NN.ZexaF.36792.dw3@aSrZfiej
ALYacGen:Variant.Doina.51920
MAXmalware (ai score=81)
MalwarebytesPUP.Optional.Eyoorun
RisingTrojan.Generic@AI.98 (RDML:fVUFeOH5SNvCh6/rsbOfbg)
SentinelOneStatic AI – Malicious PE
AVGWin64:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove PUP.Optional.Eyoorun?

PUP.Optional.Eyoorun removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment