Short bio

PUP.Optional.Sanbreel is the detection name for Sanbreel, a large family of adware that uses different methods of browser hijacking and monetizing to get their message across.

The bundled installer is usually different from the official one. The bundled installers require arguments for a full installation and are sometimes even aware of running on a virtual machine, both to hinder researchers.

Common infection method

Sanbreel adware is usually installed by a bundler, but they do create sites and offer them as separate downloads.

Avoidance advice:


Malwarebytes Anti-Malware completely removes this threat unless specifically pointed out in a dedicated removal guide.

An example of a removal guide for AppStein can be found on our forums.

Associated threats