PUP.Optional.AuslogicsDriverUpdater is Malwarebytes’ detection name for a potentially unwanted program (PUP) aimed at Windows systems and published by Auslogics.
Users of affected systems may have seen these warnings during the installation process:
this type of warnings during operations:
and this entry in the list of installed Programs and Features:
PUP.Optional.AuslogicsDriverUpdater is advertized as a sytem optimizer in the form of a driver updater. It’s usually installed by the users themselves due to misleading advertizing.
Malwarebytes protects users from PUP.Optional.AuslogicsDriverUpdater by using real-time protection.
Malwarebytes can detect and remove PUP.Optional.AuslogicsDriverUpdater without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 10/1/19 Scan Time: 9:13 AM Log File: 06416a68-e41b-11e9-8efa-00ffdcc6fdfc.json -Software Information- Version: 3.8.3.2965 Components Version: 1.0.613 Update Package Version: 1.0.12719 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 235160 Threats Detected: 38 Threats Quarantined: 38 Time Elapsed: 10 min, 4 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [3607], [341786],1.0.12719 Module: 15 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\LOCALIZER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATUPDATERSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\GOOGLEANALYTICSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\SYSTEMINFORMATIONHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DEBUGHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATPOPUPSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.SITE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.DriverHive, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERHIVEENGINE.DLL, Quarantined, [2963], [542209],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.ROUTINE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\CFAHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RESCUECENTERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 Registry Key: 3 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Auslogics\Driver Updater\Start Driver Updater оn {username} logon, Quarantined, [3607], [341781],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F7D9EDE3-BE63-463C-B77F-21095C013679}, Quarantined, [3607], [341781],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{F7D9EDE3-BE63-463C-B77F-21095C013679}, Quarantined, [3607], [341781],1.0.12719 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 1 PUP.Optional.AuslogicsDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\AUSLOGICS\DRIVER UPDATER, Quarantined, [3607], [341781],1.0.12719 File: 18 PUP.Optional.AuslogicsDriverUpdater, C:\Windows\System32\Tasks\Auslogics\Driver Updater\Start Driver Updater оn {username} logon, Quarantined, [3607], [341781],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\LOCALIZER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATUPDATERSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\GOOGLEANALYTICSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\SYSTEMINFORMATIONHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DEBUGHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATPOPUPSHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.SITE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.DriverHive, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERHIVEENGINE.DLL, Quarantined, [2963], [542209],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.ROUTINE.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\USERS\{username}\Desktop\Auslogics Driver Updater.lnk, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\CFAHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RESCUECENTERHELPER.DLL, Quarantined, [3607], [341786],1.0.12719 PUP.Optional.AuslogicsDriverUpdater, C:\USERS\{username}\DESKTOP\DRIVER-UPDATER-SETUP.EXE, Quarantined, [3607], [341785],1.0.12719 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
If you want to allow the program to connect to the Internet, for example to fetch updates, also add an exclusion of the type Allow an application to connect to the internet and use the Browse button to select the file you wish to grant access.
You may see these entries in FRST logs:
(Auslogics Labs Pty Ltd -> Auslogics) C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe Task: {F7D9EDE3-BE63-463C-B77F-21095C013679} - System32\Tasks\Auslogics\Driver Updater\Start Driver Updater оn {username} logon => C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe [4768888 2019-08-23] (Auslogics Labs Pty Ltd -> Auslogics) C:\ProgramData\BSD C:\Users\{username}\Desktop\Auslogics Driver Updater.lnk C:\Windows\system32\Tasks\Auslogics C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics C:\ProgramData\Auslogics C:\Program Files (x86)\Auslogics Auslogics Driver Updater (HKLM-x32\...\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_is1) (Version: 1.21.3.0 - Auslogics Labs Pty Ltd)
Select your language