PUA

Should I remove “PUP.Optional.Chickil”?

Malware Removal

The PUP.Optional.Chickil is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Chickil virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Anomalous binary characteristics

Related domains:

a.clickdata.37wan.com

How to determine PUP.Optional.Chickil?


File Info:

crc32: 4FDEA5FC
md5: b3124ea7826c1d66b11c9b3905898df5
name: wdgq_wqeq.exe
sha1: d30b83e145d9b5b03aa096e45b2cfb12588edffd
sha256: f556d49259aae09272d2fdcb89805dd64d83533e979d0c54edd41020fd0d57e1
sha512: 5f5a748e440787e592e26c14c50c88da0dfdd16f1fd7c5649c181f389742035241af261fba85a62956442c1c3bf0165e1ba3925c55e74c3bd9d0e5c53d218c62
ssdeep: 24576:TzTJnuz0FrK3KvSuWqekRJQd/YphZIuCgBCJjBlCI:HTJYz32Svjk3Qd/4hauCwC1V
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x706dx795e
ProductVersion: 3.0.0.0
FileDescription: x706dx795e install
Translation: 0x0804 0x03a8

PUP.Optional.Chickil also known as:

MicroWorld-eScanGen:Variant.Ursu.372699
CAT-QuickHealApplication.Agent.ZZ5
McAfeeArtemis!B3124EA7826C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004fef751 )
BitDefenderGen:Variant.Ursu.372699
K7GWAdware ( 004fef751 )
Cybereasonmalicious.7826c1
Invinceaheuristic
SymantecSMG.Heur!gen
APEXMalicious
GDataGen:Variant.Ursu.372699
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/Wews87.40707240
NANO-AntivirusTrojan.Win32.Wews87.fofick
ViRobotAdware.Wews87.999384
TencentWin32.Adware.Generic.Pbyg
EmsisoftGen:Variant.Ursu.372699 (B)
ComodoApplicUnwnt@#1zkwazubp75r5
F-SecureAdware.ADWARE/Wews87.cciac
DrWebProgram.Unwanted.3980
ZillyaAdware.Generic.Win32.113323
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.b3124ea7826c1d66
SophosGeneric PUA HK (PUA)
AviraADWARE/Wews87.mlhsq
eGambitUnsafe.AI_Score_91%
MAXmalware (ai score=99)
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftPUA:Win32/GameBox
VBA32BScope.Adware.Wews
MalwarebytesPUP.Optional.Chickil
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
RisingPUA.GameBox!8.12B2 (CLOUD)
IkarusAdWare.Wews87
FortinetRiskware/Wews87
AVGWin32:AdwareSig [Adw]
AvastWin32:AdwareSig [Adw]
Qihoo-360Win32/Trojan.Adware.37e

How to remove PUP.Optional.Chickil?

PUP.Optional.Chickil removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment