PUA

VOMPT OneUpdater (PUA) removal tips

Malware Removal

The VOMPT OneUpdater (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VOMPT OneUpdater (PUA) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine VOMPT OneUpdater (PUA)?


File Info:

name: C207A5A5D95DCA8E50A5.mlw
path: /opt/CAPEv2/storage/binaries/ac8e66b44b4639a97c06e24e803a837c9b5be3ad7faefb50830367252eb22bfe
crc32: 819A3FFA
md5: c207a5a5d95dca8e50a59bd6baa2e991
sha1: d9b7c1dd79cbca5d5c537a4301f3baccbdb74f9a
sha256: ac8e66b44b4639a97c06e24e803a837c9b5be3ad7faefb50830367252eb22bfe
sha512: 1cbe485fe6207d3c7189fd009fa5ff3f16055a87cc1911eee8bb167e404532c4dddba09f44ae54b10a179d24b135628d26918a6af9819ce8ca8045773ab49e79
ssdeep: 196608:cM/W/jM/OQzVSiCvwDGBZ2YLKR/XthnOGZQs3Xku0p6cg7wgtqCKi1f3DvmYr0qH:X1/nSvwqBZ2YLw99ZQsRk64gtqCKioqH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158866C6672D1439DB4C939A8AE17E3F9868893F24073E785943D34A3EB49B140D5ECF8
sha3_384: 685139b1a80867851194545b30117546a07579367f7ba0b79d6ee71064b2c11a85f3dbcc4ed4e85b692279e5d41ad078
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-04-11 17:52:58

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: One True Updater Company
FileDescription: 0ne TrueUpdater
FileVersion: 1.0.0.1
InternalName: OneUpdater.exe
LegalCopyright: © One True Updater Inc 2019
LegalTrademarks:
OriginalFilename: OneUpdater.exe
ProductName: 0ne True Updater
ProductVersion: 1.0.0.1
Assembly Version: 1.0.0.1

VOMPT OneUpdater (PUA) also known as:

LionicAdware.MSIL.Opesup.2!c
CAT-QuickHealPUA.WacapewFC.S20327581
MalwarebytesAdware.SpecialSearchOffer
CyrenW32/Trojan.FKL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
AlibabaAdWare:Win32/OpenSUpdater.dc7cea94
NANO-AntivirusRiskware.Win32.OpenSUpdater.iaqelh
TencentWin32.Trojan.Falsesign.Sudj
Ad-AwareGen:Variant.Adware.Cerbu.74617
SophosVOMPT OneUpdater (PUA)
EmsisoftApplication.Updater (A)
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1137248
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Adware.Cerbu.D12379
AhnLab-V3PUP/Win32.Helper.R305991
SentinelOneStatic AI – Malicious PE
FortinetAdware/OpenSUpdater
WebrootW32.Adware.Gen

How to remove VOMPT OneUpdater (PUA)?

VOMPT OneUpdater (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment