PUP.Optional.DriverSupport

Short bio

PUP.Optional.DriverSupport is a “system optimizer” called Driver Support. These so-called “system optimizers” are potentially unwanted programs (PUPs) that use intentional false positives to convince users that their Windows systems have problems. Then they try to sell you their software, claiming it will remove these problems.

Driver Support GUI

GUI of the PUP Driver Support

Symptoms

This PUP uses Scheduled Tasks to gain persistance and runs every time the user logs on. Users may see the icon in the taskbar and the start menu  and experience a slow system when the program is busy scanning. T^hey may also see pop-ups reminding them to optimize their system.

scheduled tasks

Scheduled Tasks for Driver Support

icon

icon for Driver Support

popup

popup reminding you that Driver Support found problems

Type and source of infection

The PUP is advertised as extremely useful and trusted by many.

website

the website for Driver Support

Protection

Malwarebytes blocks the installation of this PUP by detecting the installer and blocking the website and the installserver.

website

Malwarebytes blocks traffic to their website

 

installer

 

installserver

Remediation

Malwarebytes can detect and remove this potentially unwanted application without further user interaction.

  1. Please download Malwarebytes to your desktop.
  2. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  3. Then click Finish.
  4. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  5. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  6. When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  7. Restart your computer when prompted to do so.

Malwarebytes removal log

A Malwarebytes log of removal will look similar to this:

-Log Details-
Scan Date: 2/8/18
Scan Time: 10:51 AM
Log File: b2de19cc-0cb5-11e8-9439-080027750297.json
Administrator: Yes

-Software Information-
Version: 3.3.1.2183
Components Version: 1.0.262
Update Package Version: 1.0.3897
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 241875
Threats Detected: 148
Threats Quarantined: 148
Time Elapsed: 11 min, 11 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 3
PUP.Optional.DriverSupport.TskLnk, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\DRIVERSUPPORT.EXE, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\SVC\DRIVERSUPPORTAOSVC.EXE, Quarantined, [2291], [484531],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe, Quarantined, [2291], [484511],1.0.3897

Module: 18
PUP.Optional.DriverSupport.TskLnk, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\DRIVERSUPPORT.EXE, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\SVC\DRIVERSUPPORTAOSVC.EXE, Quarantined, [2291], [484531],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Common.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Common.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Common.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Communication.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Communication.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ExceptionLogging.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Interop.WUApiLib.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Common.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Practices.ObjectBuilder.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Win32.TaskScheduler.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\RuleEngine.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\RuleEngine.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ThemePack.DriverSupport.dll, Quarantined, [2291], [484511],1.0.3897

Registry Key: 30
PUP.Optional.DriverSupport, HKCU\SOFTWARE\DriverSupport, Quarantined, [2291], [484532],1.0.3897
PUP.Optional.DriverSupport, HKLM\SOFTWARE\WOW6432NODE\ACTIVEOPTIMIZATION\SVC, Quarantined, [2291], [484957],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Driver Support, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5E3E3E28-D1CA-458B-9C49-E9BE0A71870B}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{5E3E3E28-D1CA-458B-9C49-E9BE0A71870B}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Driver Support-RTMRules, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F792808D-3F2D-43C3-9CDE-0305848CA67E}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{F792808D-3F2D-43C3-9CDE-0305848CA67E}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Driver Support-RTMScan, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{622FA1D9-0F79-4CE0-B0F1-34529E64A222}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{622FA1D9-0F79-4CE0-B0F1-34529E64A222}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Driver Support-RTMUpdater, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4C6396E8-2E53-4E94-A804-D122318A7DF0}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{4C6396E8-2E53-4E94-A804-D122318A7DF0}, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E3E3E28-D1CA-458B-9C49-E9BE0A71870B}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5E3E3E28-D1CA-458B-9C49-E9BE0A71870B}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMRules, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F792808D-3F2D-43C3-9CDE-0305848CA67E}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F792808D-3F2D-43C3-9CDE-0305848CA67E}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMScan, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{622FA1D9-0F79-4CE0-B0F1-34529E64A222}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{622FA1D9-0F79-4CE0-B0F1-34529E64A222}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMUpdater, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C6396E8-2E53-4E94-A804-D122318A7DF0}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4C6396E8-2E53-4E94-A804-D122318A7DF0}, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport, HKLM\SOFTWARE\DriverSupport, Quarantined, [2291], [484521],1.0.3897
PUP.Optional.DriverSupport, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DriverSupport, Quarantined, [2291], [484524],1.0.3897
PUP.Optional.DriverSupport, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DriverSupport, Quarantined, [2291], [484524],1.0.3897
PUP.Optional.DriverSupport, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DSAO, Quarantined, [2291], [484531],1.0.3897

Registry Value: 2
PUP.Optional.DriverSupport, HKLM\SOFTWARE\WOW6432NODE\ACTIVEOPTIMIZATION\SVC|SERVER, Quarantined, [2291], [484957],1.0.3897
PUP.Optional.DriverSupport, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DSAO|DESCRIPTION, Quarantined, [2291], [484531],1.0.3897

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 13
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\PROGRAM FILES (X86)\DRIVER SUPPORT, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\RuleEngine, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDSM, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\PROGRAMDATA\DRIVER SUPPORT, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\Users\{username}\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\10.1.4.82, Quarantined, [2291], [484513],1.0.3897
PUP.Optional.DriverSupport, C:\Users\{username}\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets, Quarantined, [2291], [484513],1.0.3897
PUP.Optional.DriverSupport, C:\USERS\{username}\APPDATA\LOCAL\PC_Drivers_Headquarters, Quarantined, [2291], [484513],1.0.3897
PUP.Optional.DriverSupport, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\DRIVER SUPPORT, Quarantined, [2291], [484514],1.0.3897
PUP.Optional.DriverSupport, C:\Users\{username}\Downloads\Driver Support\Driver Support, Quarantined, [2291], [484517],1.0.3897
PUP.Optional.DriverSupport, C:\USERS\{username}\DOWNLOADS\DRIVER SUPPORT, Quarantined, [2291], [484517],1.0.3897

File: 82
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support-RTMRules, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support-RTMScan, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support-RTMUpdater, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\DRIVERSUPPORT.EXE, Quarantined, [14754], [484518],1.0.3897
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support-RTMRules, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support-RTMScan, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Driver Support-RTMUpdater, Quarantined, [14754], [-1],0.0.0
PUP.Optional.DriverSupport, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\SVC\DRIVERSUPPORTAOSVC.EXE, Quarantined, [2291], [484531],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\install.log, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\ipterbg.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\ipteup.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\ipte_svc.log, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\License.rtf, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\pmtu.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\reg.dat, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\sigverify.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\uninstall.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\svc\viometer.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Common.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.ActivationProcessors.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Common.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Common.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Communication.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.Communication.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.CPU.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.CPU.exe.config, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.ExceptionLogging.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Agent.ExceptionLogging.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\config.dat, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\cpuidsdk.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\DriverSupport.chm, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\DriverSupport.exe.config, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\DriverSupport.Updater.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\DriverSupport.Updater.exe.config, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ExceptionLogging.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ICSharpCode.SharpZipLib.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Interop.WUApiLib.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ISUninstall.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ISUninstall.exe.config, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.Downloaders.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Common.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Practices.ObjectBuilder.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Microsoft.Win32.TaskScheduler.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\RuleEngine.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\RuleEngine.XmlSerializers.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\ThemePack.DriverSupport.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\Uninstall.exe, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\Program Files (x86)\Driver Support\XPBurnComponent.dll, Quarantined, [2291], [484511],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\11481334836f4f61b3c110920048cb93.exe, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\215609eb3ff24c6ba9e214f5f6fb5867.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\312478443a844c18adeef845c32639c7.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\3360a50e06744fc08ffacdcb366a7310.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\3f2b867ce27641b4bfdc9d4a2ff92f51.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\444c8f293fac4d1b8ee44c97f5324951.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\5de611b8fd3c4f3dac06d6f80d4c0dba.jpg, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\6091981ea730431d9bf04d97348424d3.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\62f9d69a3c494d8c977596c5fc8bff96.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\a49e775fcacc484ba1935d40bf35ce1d.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\a8cf4b35c6b946b1abefd0e76d9f8704.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\DownloadResourceManager.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDRM\f8dc1c2d3a8f417aacd0142f3f1797c1.png, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\DDSM\ScanManager.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalActions.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalEnvironmentEvents.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalEnvironmentProperties.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalRules.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\RuleEngine\RuleHistoryController.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\AoServiceManager.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\CPUID.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\dd.lic, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\UXState.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\WL.dat, Quarantined, [2291], [484512],1.0.3897
PUP.Optional.DriverSupport, C:\Users\{username}\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\10.1.4.82\user.config, Quarantined, [2291], [484513],1.0.3897
PUP.Optional.DriverSupport, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support\Driver Support.lnk, Quarantined, [2291], [484514],1.0.3897
PUP.Optional.DriverSupport, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support\Uninstall Driver Support.lnk, Quarantined, [2291], [484514],1.0.3897
PUP.Optional.DriverSupport, C:\USERS\{username}\APPDATA\LOCAL\TEMP\DRIVERSUPPORT.EXE, Quarantined, [2291], [486292],1.0.3897
PUP.Optional.DriverSupport, C:\USERS\{username}\DESKTOP\DRIVERSUPPORT.EXE, Quarantined, [2291], [486292],1.0.3897

Physical Sector: 0
(No malicious items detected)

(end)

Add an exclusion

Should users wish to keep it, they can add the detections to the exclusions list. Here’s how to do it.

The Exclusions tab includes a list of items to be excluded from scans. The items may include files, folders, websites, or applications that connect to the Internet, as well as previously detected exploits.

To access the exclusions in Malwarebytes:

  • Click on the Settings tab in the left pane.
  • Click on the Exclusions tab.
  • Click the Add Exclusion button.
  • Select the exclusion type Exclude a File or Folder and use the Browse button to select the main folder for the software that you wish to keep.
  • Repeat this for any secondary folder(s) that belong to the software.
  • If you want to allow the program to connect to the internet, for example to fetch updates, add an exclusion of the type Exclude an application that Connects to the Internet and use the Browse button to select the file you wish to grant access.

Traces/IOCs

You may see these entries in FRST logs:

(PC Drivers Headquarters LP) C:\Program Files (x86)\Driver Support\DriverSupport.exe
(PC Drivers HeadQuarters LP) C:\Program Files (x86)\Driver Support\svc\DriverSupportAOsvc.exe
(PC Drivers HeadQuarters LP) C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe
C:\Windows\SysWOW64\rnd_chunk.bin
C:\Users\{username}\Downloads\Driver Support
C:\Windows\System32\Tasks\Driver Support-RTMUpdater
C:\Windows\System32\Tasks\Driver Support-RTMRules
C:\Windows\System32\Tasks\Driver Support-RTMScan
C:\Windows\System32\Tasks\Driver Support
C:\Windows\System32\Tasks\Driver Support-RTMScanRunOnce
C:\Users\{username}\AppData\Local\PC_Drivers_Headquarters
C:\ProgramData\UAB
C:\ProgramData\Driver Support
C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support
C:\Program Files (x86)\Driver Support
C:\Users\{username}\AppData\Local\Temp\DriverSupport.exe

Driver Support (HKLM-x32\…\DriverSupport) (Version: 10.1.4.82 – PC Drivers HeadQuarters LP)
Task: {1137A309-D41F-4536-A30A-9984BE1F04DD} – System32\Tasks\Driver Support-RTMScanRunOnce => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2018-01-17] (PC Drivers Headquarters LP)
Task: {4C6396E8-2E53-4E94-A804-D122318A7DF0} – System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2018-01-17] (PC Drivers Headquarters LP)
Task: {5E3E3E28-D1CA-458B-9C49-E9BE0A71870B} – System32\Tasks\Driver Support => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2018-01-17] (PC Drivers Headquarters LP)
Task: {622FA1D9-0F79-4CE0-B0F1-34529E64A222} – System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2018-01-17] (PC Drivers Headquarters LP)
Task: {F792808D-3F2D-43C3-9CDE-0305848CA67E} – System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2018-01-17] (PC Drivers Headquarters LP)

Files:

DriverSupport.exe
DriverSupportAOsvc.exe
DriverSupportAO.exe

SHA256 of the installer DriverSupport.exe: 6d9caad5db02819607a6e08cd49ae5f788b0453c0c1d923c9a8a6065fac66286

Domains:

driversupport.com

activeoptimization.com

Cybersecurity info you can’t do without

Want to stay informed on the latest news in cybersecurity? Sign up for our newsletter and learn how to protect your computer from threats.

Select your language