Malware

About “AdWare.Win32.Vosteran” infection

Malware Removal

The AdWare.Win32.Vosteran is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Vosteran virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory

How to determine AdWare.Win32.Vosteran?


File Info:

crc32: 6115EBE1
md5: 4e2e966bd91243c25ac4b71d745c7306
name: 4E2E966BD91243C25AC4B71D745C7306.mlw
sha1: a51101522e78c32bfbdc343ba380a510a26b142a
sha256: baedebbca093f952220592bc7a6b9d84e5d72049d9509a8ed599f685e8988060
sha512: 7eec84932e362c85c4098590c2b849892bc5353e6f040f409839ae2d0d5031fbbf770dd38c8ab39ca1a6c639b50d36b7d5d45ee145ac4c96510971a90107e4ec
ssdeep: 49152:2nDqSbI6DXMIbSe4xzCfLL9vSqSDNma1gBsbi9yToLrWOBY:jSXzbSZGzL9v2gOP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Quisquam
ProductVersion: 4.3.6.10
FileDescription: Quisquam Setup
Translation: 0x0000 0x04b0

AdWare.Win32.Vosteran also known as:

K7AntiVirusTrojan ( 00576e9f1 )
LionicAdware.Win32.Vosteran.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1677
ALYacTrojan.GenericKDZ.72835
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/Vosteran.73ed6082
K7GWTrojan ( 00576e9f1 )
Cybereasonmalicious.bd9124
CyrenW32/Agent.CIO.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Adware.Vosteran-9827148-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Vosteran.gen
BitDefenderApplication.DealAlpha.2.Gen
NANO-AntivirusTrojan.Win32.Kryptik.ikgvkt
ViRobotAdware.Vosteran.3063632
MicroWorld-eScanApplication.DealAlpha.2.Gen
TencentWin32.Adware.Vosteran.Pdwo
SophosDownload Assistant (PUA)
BitDefenderThetaGen:NN.ZexaE.34266.!A0@aOv9Bbdb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.FileTour.vc
FireEyeApplication.DealAlpha.2.Gen
EmsisoftApplication.DealAlpha.2.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1138320
eGambitUnsafe.AI_Score_59%
MicrosoftVirTool:MSIL/CryptInject
ArcabitApplication.DealAlpha.2.Gen
GDataTrojan.GenericKDZ.72835
McAfeeArtemis!4E2E966BD912
MAXmalware (ai score=89)
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GZFR!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.Vosteran?

AdWare.Win32.Vosteran removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment