PUA

About “PUP.Optional.Chistilka” infection

Malware Removal

The PUP.Optional.Chistilka is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Chistilka virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Detects VirtualBox through the presence of a window
  • Detects VirtualBox using WNetGetProviderName trick
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

chistilka.com
api.amplitude.com
www.google-analytics.com
chistilka.ru
stat2.chistilka.com
update.chistilka.com
pay.chistilka.com

How to determine PUP.Optional.Chistilka?


File Info:

crc32: 8589A08A
md5: 4fc5e271dfd56c5876b4cde771f2c981
name: cleaner.exe
sha1: 35b81d0a211981c886651a9e20280c560df6a503
sha256: ea95691f38e5618d6041d8f6d77939327691320e76a4cfad3e787cb079d33904
sha512: e883273a1062fc08c9502db80e4c406d1223c909df6c59796b8ef8cc2e88e1ce0d5449e7caac6ca3a2f8be4e8b177db6e6c7e6a76f8016fe473312b35320cc0c
ssdeep: 98304:YhXQ5SKwZepAX9ItHM5p7HoCCT4PU7MRT4PU7MW/YhGuv:K9PItC/IGuv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: x427x438x441x442x438x43bx43ax430.exe
FileVersion: 2.21.250
CompanyName:
LegalTrademarks1:
LegalTrademarks2:
ProductName: x427x438x441x442x438x43bx43ax430
ProductVersion: 2.21.250
FileDescription: x41fx440x43ex433x440x430x43cx43cx43dx43ex435 x43ex431x435x441x43fx435x447x435x43dx438x435 x434x43bx44f x441x43ex434x435x440x436x430x43dx438x44f x43ax43ex43cx43fx44cx44ex442x435x440x430 x432 x447x438x441x442x43ex442x435.
OriginalFilename: x427x438x441x442x438x43bx43ax430.exe
Translation: 0x0419 0x04b0

PUP.Optional.Chistilka also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.32480291
FireEyeGeneric.mg.4fc5e271dfd56c58
CAT-QuickHealPUA.RiskwareRI.S7615746
McAfeeTrojan-FRJG!4FC5E271DFD5
ZillyaDropper.Injector.Win32.86410
K7AntiVirusAdware ( 00557e001 )
BitDefenderTrojan.GenericKD.32480291
K7GWAdware ( 00557e001 )
F-ProtW32/Trojan.DJH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PUP-gen [PUP]
GDataTrojan.GenericKD.32480291
KasperskyTrojan.Win32.Khalesi.ackp
NANO-AntivirusRiskware.Win32.Chistilka.gaoqkc
RisingPUA.Chistilka!8.1114E (RDMK:cmRtazrgxz+EN7AE4IePB8RPwduH)
Ad-AwareTrojan.GenericKD.32480291
SophosVKontakteDJ (PUA)
ComodoApplication.Win32.Chistilka.A@8fktgb
F-SecureHeuristic.HEUR/AGEN.1044286
DrWebProgram.VKontakteDJ.79
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Suspicious.tc
EmsisoftApplication.AdLoad (A)
IkarusPUA.Chistilka
CyrenW32/Trojan.DJH.gen!Eldorado
JiangminTrojan.Khalesi.chq
AviraHEUR/AGEN.1044286
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Chistilka
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1EF9C23
ZoneAlarmTrojan.Win32.Khalesi.ackp
MicrosoftPUA:Win32/Conduit
ALYacTrojan.GenericKD.32480291
VBA32TrojanDropper.Injector
MalwarebytesPUP.Optional.Chistilka
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Chistilka.B potentially unwanted
SentinelOneDFI – Suspicious PE
FortinetW32/PCChist.C00D!tr
WebrootW32.Adware.Gen
AVGFileRepMalware [PUP]
Qihoo-360Generic/Trojan.Generic.897

How to remove PUP.Optional.Chistilka?

PUP.Optional.Chistilka removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment