PUA

How to remove “PUP.Optional.OneKit”?

Malware Removal

The PUP.Optional.OneKit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.OneKit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial language used in binary resources: Spanish
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
upd.upd4ter.com

How to determine PUP.Optional.OneKit?


File Info:

crc32: B01B9A41
md5: 83b09ae10f6f00ab6d2e93893e7cf602
name: 83B09AE10F6F00AB6D2E93893E7CF602.mlw
sha1: 6c4f78b3dfc8750e037486f948fc326a5dd50b0c
sha256: 1de66ceca74ce443d1ef15d47326b6c22e1d158d69cce38ce29de048d4faa045
sha512: 7301d2d9d29d4134ef59b99c43a574ad46ee6ddd62a4ba0d6f68d5da7fa00aad64ae8ae6ac7cf463cd9647d4c36934228c4b8c3461f552b61c2979340cabff50
ssdeep: 3072:ieM2nt83PkyiXMcwHmA3oPviQGBPSnLiulY7c7COk1Iy78BCvYdjQWGjANPTbHp:it2K3PziXMcwHmA3oPviQGBPSnLiulY
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xc2xa9 2012
InternalName: AppsUpd4ter.exe
FileVersion: 1.1.5.0
CompanyName:
ProductName: UpdterSw
ProductVersion: 1.1.5.0
FileDescription: UpdterSw
OriginalFilename: AppsUpd4ter.exe
Translation: 0x0000 0x04b0

PUP.Optional.OneKit also known as:

K7AntiVirusAdware ( 004b8e411 )
LionicRiskware.MSIL.Agent.1!c
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.190
CynetMalicious (score: 100)
CAT-QuickHealDownloader.Agent.A3
ALYacGen:Variant.Bulz.639773
CylanceUnsafe
SangforPUP.Win32.Vittalia.8
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 004b8e411 )
Cybereasonmalicious.10f6f0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Vittalia.M.gen potentially unwanted
APEXMalicious
AvastFileRepMetagen [PUP]
Kasperskynot-a-virus:Downloader.MSIL.Agent.zrz
BitDefenderGen:Variant.Bulz.639773
NANO-AntivirusTrojan.Win32.Vittalia.fakkgm
MicroWorld-eScanGen:Variant.Bulz.639773
TencentWin32.Trojan.Vittalia.Eawu
Ad-AwareGen:Variant.Bulz.639773
SophosGeneric PUA GM (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXFS-MW!83B09AE10F6F
FireEyeGeneric.mg.83b09ae10f6f00ab
EmsisoftGen:Variant.Bulz.639773 (B)
SentinelOneStatic AI – Malicious PE
WebrootPua.Upd4ter
AviraPUA/Vittalia.Gen
Antiy-AVLTrojan/Generic.ASMalwS.25CAA5C
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Bulz.639773
Acronissuspicious
McAfeeGenericRXFS-MW!83B09AE10F6F
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
MalwarebytesPUP.Optional.OneKit
YandexTrojan.GenAsa!liYNwl9/RYY
IkarusPUA.MSIL.Vittalia
MaxSecureTrojan.Malware.12317477.susgen
FortinetAdware/Vittalia
AVGFileRepMetagen [PUP]

How to remove PUP.Optional.OneKit?

PUP.Optional.OneKit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment