PUP.Optional.AuslogicsDriverUpdater is Malwarebytes' detection name for a potentially unwanted program (PUP) aimed at Windows systems and published by Auslogics.
Users of affected systems may have seen these warnings during the installation process:
this type of warnings during operations:
and this entry in the list of installed Programs and Features:
PUP.Optional.AuslogicsDriverUpdater is advertized as a sytem optimizer in the form of a driver updater. It's usually installed by the users themselves due to misleading advertizing.
Malwarebytes can detect and remove PUP.Optional.AuslogicsDriverUpdater without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com-Log Details- Scan Date: 10/1/19 Scan Time: 9:13 AM Log File: 06416a68-e41b-11e9-8efa-00ffdcc6fdfc.json
-Software Information- Version: 3.8.3.2965 Components Version: 1.0.613 Update Package Version: 1.0.12719 License: Premium
-System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username}
-Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 235160 Threats Detected: 38 Threats Quarantined: 38 Time Elapsed: 10 min, 4 sec
-Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect
-Scan Details- Process: 1 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [3607], [341786],1.0.12719
Module: 15 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\LOCALIZER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATUPDATERSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\GOOGLEANALYTICSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\SYSTEMINFORMATIONHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DEBUGHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATPOPUPSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.SITE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.DriverHive, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERHIVEENGINE.DLL, Quarantined, [2963], [542209],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.ROUTINE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\CFAHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RESCUECENTERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719
Registry Key: 3 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Auslogics\Driver Updater\Start Driver Updater оn {username} logon, Quarantined, [3607], [341781],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F7D9EDE3-BE63-463C-B77F-21095C013679}, Quarantined, [3607], [341781],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{F7D9EDE3-BE63-463C-B77F-21095C013679}, Quarantined, [3607], [341781],1.0.12719
Registry Value: 0 (No malicious items detected)
Registry Data: 0 (No malicious items detected)
Data Stream: 0 (No malicious items detected)
Folder: 1 PUP.Optional.AuslogicsDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\AUSLOGICS\DRIVER UPDATER, Quarantined, [3607], [341781],1.0.12719
File: 18 PUP.Optional.AuslogicsDriverUpdater, C:\Windows\System32\Tasks\Auslogics\Driver Updater\Start Driver Updater оn {username} logon, Quarantined, [3607], [341781],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\LOCALIZER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATUPDATERSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\GOOGLEANALYTICSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\SYSTEMINFORMATIONHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DEBUGHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATPOPUPSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.SITE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.DriverHive, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERHIVEENGINE.DLL, Quarantined, [2963], [542209],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.ROUTINE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\USERS\{username}\Desktop\Auslogics Driver Updater.lnk, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\CFAHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RESCUECENTERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\USERS\{username}\DESKTOP\DRIVER-UPDATER-SETUP.EXE, Quarantined, [3607], [341785],1.0.12719
Physical Sector: 0 (No malicious items detected)
WMI: 0 (No malicious items detected)
(end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
You may see these entries in FRST logs:
(Auslogics Labs Pty Ltd -> Auslogics) C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe Task: {F7D9EDE3-BE63-463C-B77F-21095C013679} - System32\Tasks\Auslogics\Driver Updater\Start Driver Updater оn {username} logon => C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe [4768888 2019-08-23] (Auslogics Labs Pty Ltd -> Auslogics) C:\ProgramData\BSD C:\Users\{username}\Desktop\Auslogics Driver Updater.lnk C:\Windows\system32\Tasks\Auslogics C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics C:\ProgramData\Auslogics C:\Program Files (x86)\AuslogicsAuslogics Driver Updater (HKLM-x32\...\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_is1) (Version: 1.21.3.0 - Auslogics Labs Pty Ltd)
Select your language