Categories: PUA

PUP.Optional.OpenCandy removal tips

The PUP.Optional.OpenCandy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.OpenCandy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
api.opencandy.com
a.tomx.xyz
www.nitropdf.com
www.bing.com

How to determine PUP.Optional.OpenCandy?


File Info:

crc32: 7614DA4Amd5: d8fd2e61ada34ea4a373a5c45b833440name: internationalprimopdf0.exesha1: 7283e8ac3398b475ab249b08001a4a08a0a4d022sha256: da9ed103a793d928eb519bf73efa06b3434da3e0e7898dfc6e6678beabf4f91dsha512: fbac5b463f23d1a3f90f2cee1567b03a4424dc73e6ce482f139a6e258c70103b2edfd0e515ec4e5910351056a4e818ef2771e2bff1f65c8961117fa718fea585ssdeep: 196608:NnXeUMZOvbdjtMVrJ5iAUhwdj1Dn9UDAW0H/1L:NnXehZORx495igP9UDe5type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUP.Optional.OpenCandy also known as:

Cylance Unsafe
F-Prot W32/OpenCandy.D.gen!Eldorado
TotalDefense Win32/OpenCandy.KSWJBbB
APEX Malicious
Kaspersky not-a-virus:Downloader.Win32.OpenCandy.aus
Alibaba Downloader:Win32/OpenCandy.36861078
NANO-Antivirus Trojan.Win32.OpenCandy.eyvhom
ViRobot Adware.Opencandy.7458096.A
AegisLab Riskware.Win32.OpenCandy.1!c
F-Secure PotentialRisk.PUA/OpenCandy.A
Zillya Adware.OpenCandy.Win32.3691
TrendMicro Adware.Win32.OpenCandy.AA
Cyren W32/OpenCandy.D.gen!Eldorado
Avira PUA/OpenCandy.A.581
MAX malware (ai score=93)
Arcabit PUP.Adware.OpenCandy
ZoneAlarm not-a-virus:Downloader.Win32.OpenCandy.aus
Microsoft PUA:Win32/CandyOpen
Malwarebytes PUP.Optional.OpenCandy
ESET-NOD32 Win32/OpenCandy potentially unsafe
TrendMicro-HouseCall Adware.Win32.OpenCandy.AA
Ikarus PUA.OpenCandy
eGambit Unsafe.AI_Score_99%
Fortinet Riskware/OpenCandy
MaxSecure Trojan.Malware.6411870.susgen

How to remove PUP.Optional.OpenCandy?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan:Win32/LummaStealer.CADV!MTB removal guide

The Trojan:Win32/LummaStealer.CADV!MTB is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

MSILHeracles.99188 removal instruction

The MSILHeracles.99188 is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

Trojan:MSIL/AgentTesla.NEC!MTB removal tips

The Trojan:MSIL/AgentTesla.NEC!MTB is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

Malware.AI.4168650666 removal instruction

The Malware.AI.4168650666 is considered dangerous by lots of security experts. When this infection is active,…

43 mins ago

About “Malware.AI.4026059104” infection

The Malware.AI.4026059104 is considered dangerous by lots of security experts. When this infection is active,…

51 mins ago

IL:Trojan.MSILZilla.120623 information

The IL:Trojan.MSILZilla.120623 is considered dangerous by lots of security experts. When this infection is active,…

52 mins ago