Threat Database Adware Adware.OpenSupdater.JB

Adware.OpenSupdater.JB

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 18
First Seen: August 28, 2023
Last Seen: March 6, 2026
OS(es) Affected: Windows

The detection of Adware.OpenSupdater.JB on your system indicates the presence of a potentially unwanted program that may be causing issues with your computer's performance and security. This type of malware is designed to display unwanted advertisements and collect user data, which can be used for various malicious purposes.

What Is Adware.OpenSupdater.JB?

Adware.OpenSupdater.JB is a type of adware that is designed to display unwanted advertisements on infected computers. It may be bundled with other software or downloaded from the internet, often without the user's knowledge or consent. This type of malware can be difficult to remove, as it may have installed itself deeply into the system and may have created multiple components to ensure its persistence.

How Adware.OpenSupdater.JB Operates

Adware.OpenSupdater.JB operates by installing itself on the infected computer and then connecting to a remote server to download and display advertisements. These advertisements may be in the form of pop-ups, banners, or sponsored search results, and may be displayed on the computer's desktop, in web browsers, or in other applications. The malware may also collect user data, such as browsing history and search queries, which can be used to target the user with specific advertisements.

In addition to displaying advertisements, Adware.OpenSupdater.JB may also have other malicious functions, such as installing additional malware or tracking the user's online activities. It may also attempt to evade detection by using various techniques, such as code obfuscation or anti-debugging methods.

Symptoms of Infection

The symptoms of Adware.OpenSupdater.JB infection may include an increase in the number of advertisements displayed on the computer, slow system performance, and unexpected crashes or freezes. The user may also notice that their web browser's homepage or search engine has been changed, or that they are being redirected to unwanted websites. In some cases, the malware may also cause the computer to become unstable or unresponsive.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Unexpected crashes or freezes
  • Changes to web browser settings
  • Redirects to unwanted websites

How to Remove Adware.OpenSupdater.JB

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malware-related extensions or add-ons.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all malware components have been removed.

Conclusion

The removal of Adware.OpenSupdater.JB requires careful attention to detail and a thorough understanding of the malware's components and behavior. By following the steps outlined above, you can help to ensure that your computer is free from this type of malware and that your personal data is protected. It is also important to take steps to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing software from the internet.

Analysis Report

General information

Family Name: Adware.OpenSupdater.JB
Signature status: Root Not Trusted

Known Samples

MD5: 850eaa03b5da2e9a78629e1b48b4dac0
SHA1: ee39571ad53ce8ee8db90c7a7f452d5eb1f2e98a
SHA256: 6F3CC43F1435D8C02DE6CA043D6E2DA584557777E64B3781DDA2320063F92FC2
File Size: 4.60 MB, 4597696 bytes
MD5: ea99f2e4a098b95c6d2c892f0de97b9b
SHA1: dae6dc9d0077e4cf78f7290e3bac1a0d3e99c86b
SHA256: 28060887E9ED6DC6488069163E577B6790E428BBF1F7E24B884F4D7EEF67C306
File Size: 5.98 MB, 5983136 bytes
MD5: acf8704c22628443fcf5b5a97cd4f49c
SHA1: b745321895a8a78dcb323090f052ff5e00f83c84
SHA256: D26E22961809164EC03C574CC75CC2A084BFCA6155CB6C837583E5EF08289198
File Size: 6.12 MB, 6115768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • BlueVioletALLCAPS Ltd
  • CadetBlueDiscipline LLC
  • ScienceSystem Co
File Description
  • BlueVioletALLCAPS
  • CadetBlueDiscipline
  • ScienceSystem
File Version 2.0.7.6
Internal Name
  • bluevioletallcaps
  • cadetbluediscipline
  • sciencesystem
Legal Copyright
  • BlueVioletALLCAPS Ltd 2021
  • CadetBlueDiscipline LLC 2022
  • ScienceSystem Co 2022
Original Filename
  • bluevioletallcaps.exe
  • cadetbluediscipline.exe
Product Name
  • BlueVioletALLCAPS
  • CadetBlueDiscipline
  • ScienceSystem
Product Version 2.0.7.6

Digital Signatures

Signer Root Status
GrantDecoration GrantDecoration Root Not Trusted
HadassahPhenomenon HadassahPhenomenon Root Not Trusted
OlofsenVliert OlofsenVliert Root Not Trusted

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 17,154
Potentially Malicious Blocks: 56
Whitelisted Blocks: 16,691
Unknown Blocks: 407

Visual Map

? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? x ? ? 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 0 0 ? ? ? 0 0 0 0 ? ? ? ? ? 0 x ? ? ? ? 0 ? ? 0 1 ? 0 x 0 0 0 ? 0 0 0 ? x x x x ? x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 ? ? ? ? ? ? ? x 0 ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 ? 0 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 1 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 1 0 ? ? ? ? 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? 0 ? x 0 x 0 ? x 0 0 0 0 0 x 0 0 0 0 ? ? 0 0 0 0 0 0 0 1 0 ? ? 0 1 ? 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AITA
  • Agent.FRFD
  • ConvertAd.X
  • Farfli.NB
  • Lotok.F
Show More
  • OpenSUpdater.AL
  • OpenSUpdater.PB
  • OpenSUpdater.TD
  • PC Accelerator.H
  • Rugmi.GI
  • Rugmi.K
  • Sicos.A

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Related Posts

Trending

Most Viewed

Loading...