PUA

PUP.Optional.SMSPay (file analysis)

Malware Removal

The PUP.Optional.SMSPay is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.SMSPay virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUP.Optional.SMSPay?


File Info:

crc32: FCDE9907
md5: 7addb06f8b8a31ccfe781d5346767d93
name: 7ADDB06F8B8A31CCFE781D5346767D93.mlw
sha1: d80b1bba750a03749b2ddf288baf13ae00d48ea9
sha256: 2c8c26000b968ff0cf2b9f96be9b2807ffddf4e87598f152eb602528d5f2b407
sha512: 34181b644de32513fedfd7d2ba4b730fa7d4452226a172af236117d53ac32f874f77dba6139eecf5120f36a3841ce81911f7783ed756b00478a6db1e2695beed
ssdeep: 3072:wgXdZt9P6D3XJgkmNK3CvQNOOf4OhaFWjmAo/NhD15:we34GkmNaCIcC/NyAYDX
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

PUP.Optional.SMSPay also known as:

K7AntiVirusAdware ( 0050b6031 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.33552
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaTrojan.Bayrob.Win32.33723
SangforPUP.Win32.FileconfigDown.8
K7GWAdware ( 0050b6031 )
Cybereasonmalicious.a750a0
SymantecTrojan.Gen
ESET-NOD32Win32/FileconfigDown.A potentially unwanted
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyHEUR:Trojan.Win32.Bayrob.gen
NANO-AntivirusTrojan.Nsis.StartPage.dpyblh
SophosMal/Generic-S
ComodoMalware@#2j4zpipzm8wyq
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXCF.cc
SentinelOneStatic AI – Suspicious PE
AviraTR/ArchSMS.Gen
Antiy-AVLTrojan/Generic.ASMalwNS.F55
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Bayrob
McAfeeArtemis!7ADDB06F8B8A
VBA32suspected of Trojan.Downloader.gen
MalwarebytesPUP.Optional.SMSPay
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove PUP.Optional.SMSPay?

PUP.Optional.SMSPay removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment