Malware

Win32/AllerUpdater.A potentially unwanted malicious file

Malware Removal

The Win32/AllerUpdater.A potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AllerUpdater.A potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Detects Bochs through the presence of a registry key
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/AllerUpdater.A potentially unwanted?


File Info:

name: FC2CF42892C0CD1FF001.mlw
path: /opt/CAPEv2/storage/binaries/64440a1df54282dc743f84b9814a6112bd1a23765f0f11a7102dd5b11bc708da
crc32: 257378A4
md5: fc2cf42892c0cd1ff00163beeab66993
sha1: 4e1126859c286e28d2780df85a9073fadc19379f
sha256: 64440a1df54282dc743f84b9814a6112bd1a23765f0f11a7102dd5b11bc708da
sha512: a5f054b1a1759cc1c9b8c030f9800773b8b70e8de517fea114d6cceeb7797582023e9b0ace17147cf1b718983a5284ede265ce253e2d1ee1e7f1b3d4fab88a24
ssdeep: 12288:5Sd82Rm2jAjz+Zj5MkH10k+DykZu6xXajZyuCZLKigt9f0sip:odDRm2jA/ktMaCfEhZcKiS9f0xp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133F402157659D992EF7B1B756C03A87E47B43C21AF78D03EA381BE6E1BB93E24148043
sha3_384: df7e0315cc38f7d047f17c1493b9a4ba1ffd58dc1bd7d507e6699884eb0d28b45b74e988e69a632c5f973f03011aebb2
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2018-12-15 22:24:22

Version Info:

0: [No Data]

Win32/AllerUpdater.A potentially unwanted also known as:

CylanceUnsafe
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/AllerUpdater.A potentially unwanted
APEXMalicious
ClamAVWin.Dropper.Vidar-9938280-0
SophosGeneric PUA EO (PUA)
Antiy-AVLTrojan/Win32.Wacatac
PandaPUP/InstallCore

How to remove Win32/AllerUpdater.A potentially unwanted?

Win32/AllerUpdater.A potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment