PUA

PUP.Optional.OpenCandy removal tips

Malware Removal

The PUP.Optional.OpenCandy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.OpenCandy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
api.opencandy.com
a.tomx.xyz
www.nitropdf.com
www.bing.com

How to determine PUP.Optional.OpenCandy?


File Info:

crc32: 7614DA4A
md5: d8fd2e61ada34ea4a373a5c45b833440
name: internationalprimopdf0.exe
sha1: 7283e8ac3398b475ab249b08001a4a08a0a4d022
sha256: da9ed103a793d928eb519bf73efa06b3434da3e0e7898dfc6e6678beabf4f91d
sha512: fbac5b463f23d1a3f90f2cee1567b03a4424dc73e6ce482f139a6e258c70103b2edfd0e515ec4e5910351056a4e818ef2771e2bff1f65c8961117fa718fea585
ssdeep: 196608:NnXeUMZOvbdjtMVrJ5iAUhwdj1Dn9UDAW0H/1L:NnXehZORx495igP9UDe5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUP.Optional.OpenCandy also known as:

CylanceUnsafe
F-ProtW32/OpenCandy.D.gen!Eldorado
TotalDefenseWin32/OpenCandy.KSWJBbB
APEXMalicious
Kasperskynot-a-virus:Downloader.Win32.OpenCandy.aus
AlibabaDownloader:Win32/OpenCandy.36861078
NANO-AntivirusTrojan.Win32.OpenCandy.eyvhom
ViRobotAdware.Opencandy.7458096.A
AegisLabRiskware.Win32.OpenCandy.1!c
F-SecurePotentialRisk.PUA/OpenCandy.A
ZillyaAdware.OpenCandy.Win32.3691
TrendMicroAdware.Win32.OpenCandy.AA
CyrenW32/OpenCandy.D.gen!Eldorado
AviraPUA/OpenCandy.A.581
MAXmalware (ai score=93)
ArcabitPUP.Adware.OpenCandy
ZoneAlarmnot-a-virus:Downloader.Win32.OpenCandy.aus
MicrosoftPUA:Win32/CandyOpen
MalwarebytesPUP.Optional.OpenCandy
ESET-NOD32Win32/OpenCandy potentially unsafe
TrendMicro-HouseCallAdware.Win32.OpenCandy.AA
IkarusPUA.OpenCandy
eGambitUnsafe.AI_Score_99%
FortinetRiskware/OpenCandy
MaxSecureTrojan.Malware.6411870.susgen

How to remove PUP.Optional.OpenCandy?

PUP.Optional.OpenCandy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment