PUA

How to remove “PUP.Optional.Thunder”?

Malware Removal

The PUP.Optional.Thunder is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Thunder virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.

How to determine PUP.Optional.Thunder?


File Info:

crc32: 99F4B97B
md5: c31af8a3f6a1b0e1aca5110f88082bac
name: C31AF8A3F6A1B0E1ACA5110F88082BAC.mlw
sha1: 7b633b0b3c259677051a4d94320ff751a18546f2
sha256: 24bf6776cb4b6bd86601647182a7edc3d8e623da1ff87ad104460af1518a376f
sha512: b0133c39f9e7e551ff0c495718bf18f8c3a084aed870a69fd2d3f19a10a829ae23473711d1f9ecd40e3d2d52e32091c8b10a377564d4020c3570d39c2cd22958
ssdeep: 3072:3bVvoKfxrIQ6AOwMEDhj7YlTb0roSvoEHNHLj/wx7h8EKAi93JdiUTQYHZbja:rVhdIQ6AOwMYVtZ+tCEKn95dP5bj
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.695
InternalName: install.exe
FileVersion: 1.0.0.695
ProductVersion: 1.0.0.695
FileDescription:
OriginalFilename: install.exe

PUP.Optional.Thunder also known as:

K7AntiVirusAdware ( 004dc58d1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Application.Bundler.Amonetize.74
CylanceUnsafe
ZillyaTool.Bundler.Win32.29369
SangforPUP.Win32.Amonetize.8
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:MSIL/Amonetize.04dd251d
K7GWAdware ( 004dc58d1 )
Cybereasonmalicious.3f6a1b
CyrenW32/S-524e6fcc!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Amonetize.AF potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Packed.Susppack-9881847-0
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Agent.gen
BitDefenderGen:Variant.Application.Bundler.Amonetize.74
NANO-AntivirusRiskware.Win32.Amonetize.fiunyv
MicroWorld-eScanGen:Variant.Application.Bundler.Amonetize.74
TencentWin32.Adware.Generic.Suxe
Ad-AwareGen:Variant.Application.Bundler.Amonetize.74
SophosGeneric PUA HL (PUA)
ComodoApplication.MSIL.Amonetize.AF@67z1tc
BitDefenderThetaGen:NN.ZemsilF.34266.km0@au!e6ek
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.c31af8a3f6a1b0e1
EmsisoftGen:Variant.Application.Bundler.Amonetize.74 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
AviraADWARE/Amonetize.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1713CB3
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywarePUP.Amonetize/Variant
GDataGen:Variant.Application.Bundler.Amonetize.74
AhnLab-V3PUP/Win32.Generic.R173258
Acronissuspicious
McAfeeArtemis!C31AF8A3F6A1
MAXmalware (ai score=75)
MalwarebytesPUP.Optional.Thunder
PandaTrj/GdSda.A
YandexPUA.Agent!69iMxKo9J0o
Ikarusnot-a-virus:AdWare.Amonetize
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove PUP.Optional.Thunder?

PUP.Optional.Thunder removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment