Malware

BrowserModifier:Win32/Vonteera malicious file

Malware Removal

The BrowserModifier:Win32/Vonteera is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BrowserModifier:Win32/Vonteera virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (10 unique times)
  • A named pipe was used for inter-process communication
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key
  • Attempts to modify browser security settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

s3.amazonaws.com
ocsp.digicert.com
flashcart-helper.googlecode.com
www.gogostats.info
accounts.youtube.com
clients2.googleusercontent.com
fonts.gstatic.com
ocsp.pki.goog
curl.haxx.se
www.acdcads.com

How to determine BrowserModifier:Win32/Vonteera?


File Info:

crc32: 2FA70297
md5: 986297ce826e86477cf9003ad499945c
name: 986297CE826E86477CF9003AD499945C.mlw
sha1: 84e201978701459487a31e54438efa0dea612e17
sha256: 41ee88db50b0110c301b6769eefe2169157640776d114702c271d0481fe479d0
sha512: a8b1f985502f2848f556ecc8bcf2db2678b70c0673b891219bdfdad077b56d0556f46d49b5d24b3cbc51d1975a2c727fa51f3720c8e33a8de1aa72e70d174b78
ssdeep: 12288:Q5ILkfA7D8ZHHLzmMYnBLr2jD7HXXgjdOXtAAC0s:aILkA3iHLwh6D7HngjdOXOAXs
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: 7zFM.exe
FileVersion: 9.22
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.22
FileDescription: 7-Zip File Manager
OriginalFilename: 7zFM.exe
Translation: 0x0409 0x04b0

BrowserModifier:Win32/Vonteera also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 004ba2e11 )
Elasticmalicious (high confidence)
DrWebAdware.Volaro.8
CynetMalicious (score: 99)
ALYacGen:Trojan.Downloader.CmMfamIyyupi
CylanceUnsafe
SangforRansom.Win32.Blocker.krde
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 004ba2e11 )
Cybereasonmalicious.e826e8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Vonteera.J
APEXMalicious
AvastWin32:Adware-CZS [Adw]
KasperskyTrojan-Ransom.Win32.Blocker.krde
BitDefenderGen:Trojan.Downloader.CmMfamIyyupi
NANO-AntivirusTrojan.Win32.Agent.dyupsx
MicroWorld-eScanGen:Trojan.Downloader.CmMfamIyyupi
TencentWin32.Trojan.Blocker.Htvm
Ad-AwareGen:Trojan.Downloader.CmMfamIyyupi
SophosGeneric PUA IE (PUA)
ComodoApplicUnwnt@#36h45kkflta7e
BitDefenderThetaAI:Packer.423A086E1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.986297ce826e8647
EmsisoftGen:Trojan.Downloader.CmMfamIyyupi (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.gjyl
AviraTR/Vonteera.A.284
Antiy-AVLTrojan/Generic.ASMalwS.163995D
MicrosoftBrowserModifier:Win32/Vonteera
GDataGen:Trojan.Downloader.CmMfamIyyupi
AhnLab-V3Trojan/Win32.Generic.R163962
Acronissuspicious
McAfeeArtemis!986297CE826E
MAXmalware (ai score=87)
VBA32BScope.Adware.Volaro
MalwarebytesAdware.Vonteera
PandaTrj/CI.A
YandexTrojan.GenAsa!X8fmaUltJQE
IkarusTrojan.Vonteera
FortinetRiskware/Vonteera
AVGWin32:Adware-CZS [Adw]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASRkA

How to remove BrowserModifier:Win32/Vonteera?

BrowserModifier:Win32/Vonteera removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment