PUA

PUP.Optional.OneUpdater removal

Malware Removal

The PUP.Optional.OneUpdater is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.OneUpdater virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Performs some HTTP requests
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUP.Optional.OneUpdater?


File Info:

crc32: 44815AAB
md5: be946d3f382cf3e612bc51c71f4cddd7
name: BE946D3F382CF3E612BC51C71F4CDDD7.mlw
sha1: 2ad3c3444ac5a75cad4a4bb08cee42afad02310a
sha256: 2a2bcd5bb7c48b2641d0051e09351ca5359797c7615be452b1f5cc45b1dd1757
sha512: 03b09e1a8caee23fada7cd00dc2f47e56372c337ebb95515458b8924b8c516a07425ac3fb5d39c1457ef45d68f531a3f12b789db9a0b7bc2162c674b5b74b54d
ssdeep: 196608:RM/W/jM/OQzVSiCvwDGBZ2YLKR/XthnOGZQs3Xku0p6cg7wgtqCKi1f3DvmYr0q8:G1/nSvwqBZ2YLw99ZQsRk64gtqCKioq8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Primero Updater Inc 2020
Assembly Version: 1.0.0.1
InternalName: OneUpdater.exe
FileVersion: 1.0.0.1
CompanyName: Primero Updater Company
LegalTrademarks:
Comments:
ProductName: Primero Updater
ProductVersion: 1.0.0.1
FileDescription: Primero Updater
OriginalFilename: OneUpdater.exe

PUP.Optional.OneUpdater also known as:

DrWebAdware.Downware.19643
MicroWorld-eScanGen:Variant.Adware.Bulz.1650
CAT-QuickHealPUA.WacapewFC.S20327581
ALYacGen:Variant.Adware.Bulz.1650
SangforAdware.Win32.Agent.gen
Cybereasonmalicious.f382cf
CyrenW32/Trojan.FKL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.OpenSUpdater.D
APEXMalicious
AvastWin32:AdwareSig [Adw]
CynetMalicious (score: 99)
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Agent.gen
BitDefenderGen:Variant.Adware.Bulz.1650
NANO-AntivirusRiskware.Win32.OpenSUpdater.iukxcj
TencentMsil.Adware.Opensupdater.Pjdk
Ad-AwareGen:Variant.Adware.Bulz.1650
SophosVOMPT OneUpdater (PUA)
F-SecureHeuristic.HEUR/AGEN.1137248
FireEyeGeneric.mg.be946d3f382cf3e6
EmsisoftApplication.Updater (A)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137248
Antiy-AVLTrojan/Generic.ASMalwS.3095A91
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Adware.Bulz.1650
AhnLab-V3PUP/Win32.Helper.R305991
MAXmalware (ai score=60)
VBA32TScope.Trojan.MSIL
MalwarebytesPUP.Optional.OneUpdater
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/OpenSUpdater
AVGWin32:AdwareSig [Adw]

How to remove PUP.Optional.OneUpdater?

PUP.Optional.OneUpdater removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment