PUA

PUA:Win32/VOPackage removal guide

Malware Removal

The PUA:Win32/VOPackage is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/VOPackage virus can do?

  • Presents an Authenticode digital signature
  • Attempts to connect to a dead IP:Port (7 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Queries information on disks, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

chistilka.ru
apps.identrust.com
stat2.chistilka.com
update.chistilka.com
crt.usertrust.com

How to determine PUA:Win32/VOPackage?


File Info:

crc32: 07F2D76A
md5: ab9ebac189b543f8493482f8c7a59103
name: bin-2.21.157.exe
sha1: da9e5f85570daaffe9622ab5964e1078ab6dc867
sha256: adf1a69895bc816818db9fd146286f7d01f547d5ab79409f35b1e004b70a7891
sha512: ac4b39a94f17615a2a85c2dfc8ee564431190d1bbe8f4297a184ed7765273600438cd142de2b0b93b7ca21192bb7044a7cb63bbfe236fd2b9acd36197b5edd33
ssdeep: 98304:WAA3/xt/kvQTAvAP7okF5pysbSXd4h+uCSsPxuoG4IRsnJq/:WAA3/zkvQT/rX5SXi8WsZx8sw
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: x427x438x441x442x438x43bx43ax430.exe
FileVersion: 2.21.157
CompanyName:
LegalTrademarks1:
LegalTrademarks2:
ProductName: x427x438x441x442x438x43bx43ax430
ProductVersion: 2.21.157
FileDescription: x41fx440x43ex433x440x430x43cx43cx43dx43ex435 x43ex431x435x441x43fx435x447x435x43dx438x435 x434x43bx44f x443x434x430x43bx435x43dx438x44f x432x440x435x434x43ex43dx43ex441x43dx44bx445 x444x430x439x43bx43ex432 x438 x440x430x441x448x438x440x435x43dx438x439.
OriginalFilename: x427x438x441x442x438x43bx43ax430.exe
Translation: 0x0419 0x04b0

PUA:Win32/VOPackage also known as:

FireEyeGeneric.mg.ab9ebac189b543f8
McAfeeArtemis!AB9EBAC189B5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
Invinceaheuristic
CyrenW32/WinFixer.G.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
GDataWin32.Application.PCChist.A
KasperskyHoax.Win32.PCChist.gen
AlibabaRiskWare:Win32/PCChist.b64c45a1
AegisLabAdware.Win32.ExtGPi.2!c
RisingHoax.PCChist!8.10993 (CLOUD)
EmsisoftApplication.Toolbar (A)
ComodoMalware@#r1yi2tz08u23
F-SecureHeuristic.HEUR/AGEN.1100689
DrWebProgram.VKontakteDJ.70
ZillyaTool.PCChist.Win32.38
McAfee-GW-EditionBehavesLike.Win32.TrojanPCChist.rc
SophosSOFT-EKSPERTY Cleaner (PUA)
IkarusTrojan.PSW.Agent
F-ProtW32/WinFixer.G.gen!Eldorado
JiangminHoax.PCChist.b
AviraHEUR/AGEN.1100689
Antiy-AVLHackTool[Hoax]/Win32.PCChist
Endgamemalicious (high confidence)
ZoneAlarmHoax.Win32.PCChist.gen
MicrosoftPUA:Win32/VOPackage
AhnLab-V3Malware/Gen.Generic.C3133046
Acronissuspicious
VBA32Trojan.Tiggre
MalwarebytesPUP.Optional.SoftEksperty
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Chistilka.B potentially unwanted
TencentMalware.Win32.Gencirc.10cd7fd0
YandexRiskware.Agent!
FortinetW32/PCChist.A!tr
BitDefenderThetaGen:NN.ZexaF.34126.@pLfaaWITXdk
AVGFileRepMetagen [Malware]
Cybereasonmalicious.189b54
Qihoo-360Generic/Trojan.PSW.dcb

How to remove PUA:Win32/VOPackage?

PUA:Win32/VOPackage removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment