Categories: PUA

About “PUP.Optional.Chistilka” infection

The PUP.Optional.Chistilka is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Chistilka virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Detects VirtualBox through the presence of a window
  • Detects VirtualBox using WNetGetProviderName trick
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

chistilka.com
api.amplitude.com
www.google-analytics.com
chistilka.ru
stat2.chistilka.com
update.chistilka.com
pay.chistilka.com

How to determine PUP.Optional.Chistilka?


File Info:

crc32: 8589A08Amd5: 4fc5e271dfd56c5876b4cde771f2c981name: cleaner.exesha1: 35b81d0a211981c886651a9e20280c560df6a503sha256: ea95691f38e5618d6041d8f6d77939327691320e76a4cfad3e787cb079d33904sha512: e883273a1062fc08c9502db80e4c406d1223c909df6c59796b8ef8cc2e88e1ce0d5449e7caac6ca3a2f8be4e8b177db6e6c7e6a76f8016fe473312b35320cc0cssdeep: 98304:YhXQ5SKwZepAX9ItHM5p7HoCCT4PU7MRT4PU7MW/YhGuv:K9PItC/IGuvtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: InternalName: x427x438x441x442x438x43bx43ax430.exeFileVersion: 2.21.250CompanyName: LegalTrademarks1: LegalTrademarks2: ProductName: x427x438x441x442x438x43bx43ax430ProductVersion: 2.21.250FileDescription: x41fx440x43ex433x440x430x43cx43cx43dx43ex435 x43ex431x435x441x43fx435x447x435x43dx438x435 x434x43bx44f x441x43ex434x435x440x436x430x43dx438x44f x43ax43ex43cx43fx44cx44ex442x435x440x430 x432 x447x438x441x442x43ex442x435.OriginalFilename: x427x438x441x442x438x43bx43ax430.exeTranslation: 0x0419 0x04b0

PUP.Optional.Chistilka also known as:

Bkav W32.AIDetectVM.malware
MicroWorld-eScan Trojan.GenericKD.32480291
FireEye Generic.mg.4fc5e271dfd56c58
CAT-QuickHeal PUA.RiskwareRI.S7615746
McAfee Trojan-FRJG!4FC5E271DFD5
Zillya Dropper.Injector.Win32.86410
K7AntiVirus Adware ( 00557e001 )
BitDefender Trojan.GenericKD.32480291
K7GW Adware ( 00557e001 )
F-Prot W32/Trojan.DJH.gen!Eldorado
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:PUP-gen [PUP]
GData Trojan.GenericKD.32480291
Kaspersky Trojan.Win32.Khalesi.ackp
NANO-Antivirus Riskware.Win32.Chistilka.gaoqkc
Rising PUA.Chistilka!8.1114E (RDMK:cmRtazrgxz+EN7AE4IePB8RPwduH)
Ad-Aware Trojan.GenericKD.32480291
Sophos VKontakteDJ (PUA)
Comodo Application.Win32.Chistilka.A@8fktgb
F-Secure Heuristic.HEUR/AGEN.1044286
DrWeb Program.VKontakteDJ.79
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Suspicious.tc
Emsisoft Application.AdLoad (A)
Ikarus PUA.Chistilka
Cyren W32/Trojan.DJH.gen!Eldorado
Jiangmin Trojan.Khalesi.chq
Avira HEUR/AGEN.1044286
MAX malware (ai score=86)
Antiy-AVL GrayWare/Win32.Chistilka
Endgame malicious (high confidence)
Arcabit Trojan.Generic.D1EF9C23
ZoneAlarm Trojan.Win32.Khalesi.ackp
Microsoft PUA:Win32/Conduit
ALYac Trojan.GenericKD.32480291
VBA32 TrojanDropper.Injector
Malwarebytes PUP.Optional.Chistilka
Panda Trj/Genetic.gen
ESET-NOD32 a variant of Win32/Chistilka.B potentially unwanted
SentinelOne DFI – Suspicious PE
Fortinet W32/PCChist.C00D!tr
Webroot W32.Adware.Gen
AVG FileRepMalware [PUP]
Qihoo-360 Generic/Trojan.Generic.897

How to remove PUP.Optional.Chistilka?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.1586757393 removal guide

The Malware.AI.1586757393 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

About “Malware.AI.794055156” infection

The Malware.AI.794055156 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Trojan:Win32/MysticStealer.ASAX!MTB removal instruction

The Trojan:Win32/MysticStealer.ASAX!MTB is considered dangerous by lots of security experts. When this infection is active,…

44 mins ago

How to remove “Troj/Dloadr-DNE”?

The Troj/Dloadr-DNE is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Ransom.Loki.22424 information

The Ransom.Loki.22424 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Bulz.240342 removal guide

The Bulz.240342 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago