PUA

PUP.Optional.OneSafePCCleaner removal

Malware Removal

The PUP.Optional.OneSafePCCleaner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.OneSafePCCleaner virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
stats.onesafesoftware.com
notifications.onesafesoftware.com
webtools.onesafesoftware.com
webtools.avanquest.com

How to determine PUP.Optional.OneSafePCCleaner?


File Info:

crc32: 5606C69F
md5: 4a6e3dbb660b6dd966222c880e6fdd1e
name: 478801c3-72c8-4866-8521-95e06eacf6da_onesafe_pc_cleaner_7_retail.exe
sha1: 12a8b7de0fab05c0517bb6d3a21a213c0b71a6d8
sha256: 2da72bc2a523a04c5ef527b344a55446011ce75add47d301c7bdb7f3e6ecb6c5
sha512: be93ff552200c641d9f9e61d261e1f85810cb8ace5a766196a4e74a87b7bf981f29c67af2040c13ff87ffa79eff755c9b41532cae1fa6f708fdcc0c10c750ecf
ssdeep: 98304:UX49jgrgLp9jsinyYEI+CoGp91rkX0OHasIQ1cz6qnfPyazx1z:io0gLp1si0Gp91AHKVz6CfPyav
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Avanquest Software
FileVersion: 7.0.0.59
CompanyName: Avanquest Software
Comments: This installation was built with Inno Setup.
ProductName: OneSafe PC Cleaner
ProductVersion: 7.0.0.59
FileDescription: OneSafe PC Cleaner
OriginalFileName:
Translation: 0x0000 0x04b0

PUP.Optional.OneSafePCCleaner also known as:

McAfeeArtemis!4A6E3DBB660B
CylanceUnsafe
SangforMalware
K7AntiVirusAdware ( 0055975e1 )
K7GWAdware ( 0055975e1 )
APEXMalicious
GDataWin32.Application.AvanOSPC.A
KasperskyHEUR:Hoax.Win32.SafeCleaner.gen
AlibabaRiskWare:Win32/SafeCleaner.bd601804
NANO-AntivirusRiskware.Win32.SafeCleaner.gfjwqw
TencentWin32.Trojan-psw.Safecleaner.Pdwo
SophosGeneric PUA OP (PUA)
ComodoMalware@#204j8phibv7v1
F-SecureTrojan.TR/Redcap.zidad
DrWebProgram.Unwanted.4549
TrendMicroPUA.Win32.PCCleaner.AU
McAfee-GW-EditionArtemis
MaxSecureTrojan.Malware.5539.susgen
CyrenW32/Application.QZQS-8296
AviraappOSPCNotifications.exe
ZoneAlarmHEUR:Hoax.Win32.SafeCleaner.gen
MicrosoftPUA:Win32/SpeedingUpMyPC
MalwarebytesPUP.Optional.OneSafePCCleaner
PandaPUP/PCCleaner
ESET-NOD32a variant of Win32/Avanquest.C potentially unwanted
TrendMicro-HouseCallPUA.Win32.PCCleaner.AU
RisingHoax.SafeCleaner!8.110C6 (CLOUD)
FortinetRiskware/SafeCleaner
Qihoo-360HEUR/QVM42.3.2BD5.Malware.Gen

How to remove PUP.Optional.OneSafePCCleaner?

PUP.Optional.OneSafePCCleaner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment