PUA Spy

About “PUP.Optional.NeoSpy” infection

Malware Removal

The PUP.Optional.NeoSpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.NeoSpy virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Installs WinPCAP

How to determine PUP.Optional.NeoSpy?


File Info:

name: 0A7E256EAAF35CE555EB.mlw
path: /opt/CAPEv2/storage/binaries/f81b306764f038d4fd1e128a982136fc6d5516a6fc9cd5d62baafd74cbc46a5e
crc32: 2ED15295
md5: 0a7e256eaaf35ce555eb1895dc093f6d
sha1: d2abdc90a3d5da82ea1ede8a68d45a5cce846c03
sha256: f81b306764f038d4fd1e128a982136fc6d5516a6fc9cd5d62baafd74cbc46a5e
sha512: 2a485343f5f875f51d3e564802858dd3ac7cde10d816926687bcc572f8cef36255a5770bd13d75894579ac7378e0ea90572c0c45d6d016bb12d5d0966db558ff
ssdeep: 98304:7Aqp9/+YrhOJs6f+1ZRe9gp2an3paSgDoP8/rK8ojt+U+P:7DpxPrh8nf6ZRh7g1DfTK8Yt9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C163343D2948A3BFCB413F488DFC1B7217CF1DC2765ABD7A29AD2C2A0A42E1657452D
sha3_384: 43ff5d113382ed4a9e5ed9ffb0489ebebd949b3b9abec5ec0a60ce0c4e60f8b960fd18c8d590cea03ac0e9a538665f0b
ep_bytes: e80a000000e97affffffcccccccccc8b
timestamp: 2008-04-13 18:32:45

Version Info:

CompanyName: MC-Soft
FileDescription:
FileVersion: 4.1.11.61
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 4.1
Comments:
Translation: 0x0409 0x04e4

PUP.Optional.NeoSpy also known as:

LionicRiskware.Win32.NeoSpy.1!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.0a7e256eaaf35ce5
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004d38111 )
K7GWUnwanted-Program ( 004d38111 )
ESET-NOD32multiple detections
Kasperskynot-a-virus:Monitor.Win32.NeoSpy.qs
NANO-AntivirusTrojan.Win32.NeoSpy.bxnapz
AvastWin32:NeoSpy [PUP]
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#t687oky0ag00
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric Dropper!cou
SentinelOneStatic AI – Malicious PE
JiangminMonitor.NeoSpy.e
WebrootSystem.Monitor.Neospy
AviraTR/Dropper.Gen
MAXmalware (ai score=97)
Antiy-AVLTrojan/Generic.ASMalwS.C43920
MicrosoftTrojan:Win32/Occamy.CF8
ViRobotAdware.Neospy.4090880
ZoneAlarmnot-a-virus:Monitor.Win32.NeoSpy.qs
CynetMalicious (score: 99)
VBA32BScope.Trojan.Detplock
MalwarebytesPUP.Optional.NeoSpy
APEXMalicious
TencentWin32.Risk.Keylogger.Gly
FortinetRiskware/NeoSpy
AVGWin32:NeoSpy [PUP]
MaxSecureTrojan.Malware.300983.susgen

How to remove PUP.Optional.NeoSpy?

PUP.Optional.NeoSpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment