Malware

About “Rogue:Win32/Vakcune” infection

Malware Removal

The Rogue:Win32/Vakcune is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/Vakcune virus can do?

  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid

How to determine Rogue:Win32/Vakcune?


File Info:

name: BEAB6C8136A9EDFD9433.mlw
path: /opt/CAPEv2/storage/binaries/9f843ddd38e4a232af9834acd83f9c2d5404bd6263ad110c4bfab41680fe5b54
crc32: 2B71FAD6
md5: beab6c8136a9edfd943344130bf958b5
sha1: 6457ba8a7d9c99cad9017d710c8ffc5811a9cff5
sha256: 9f843ddd38e4a232af9834acd83f9c2d5404bd6263ad110c4bfab41680fe5b54
sha512: 896ec567d2eccd1e54a885422db1ebdbc1ec20011a96a476cdc8b308ac5631da256d46236a0eea070b5d447463a47d0c125d0b80b194cd77b85e94d43e884d0f
ssdeep: 3072:UaXdtjVvF/QleyZL3tjDP8pH+NNpP2HOQiysnLVc5d0USvSdrqJLhN/DwmdK182Y:U0vds3tXeylZy8LSV9SP2SWAjLj6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A548E33B2B1C8B7C65300B38ED3A7B6B5F5ED14CA218A836799BF1DBE715824236115
sha3_384: 17884edfbbf9f129513ce5cc0c7cddf8b4183f635145795e3104c24197b3581478e34ac31e16463ad88d47ab92a8247d
ep_bytes: 558bec6aff68e8fc420068d066410064
timestamp: 2010-07-07 00:35:44

Version Info:

Comments:
CompanyName:
FileDescription: VDMon
FileVersion: 1, 0, 1, 6
InternalName: VDMon
LegalCopyright: Copyright (C) 2010 By Ebiz Networks Corp.
LegalTrademarks:
OriginalFilename: VDMon.EXE
PrivateBuild:
ProductName: VDMon
ProductVersion: 1, 0, 1, 6
SpecialBuild:
Translation: 0x0412 0x04b0

Rogue:Win32/Vakcune also known as:

BkavW32.Common.11006536
LionicAdware.Win32.VirusCure.2!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanAdware.Generic.3134723
FireEyeAdware.Generic.3134723
SkyhighGeneric FakeAV.ck
ALYacAdware.Generic.3134723
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.42978
SangforAdware.Win32.Viruscure.Vrdd
AlibabaAdWare:Win32/VirusCure.6ffb9376
K7GWAdware ( 004bd0b01 )
K7AntiVirusAdware ( 004bd0b01 )
ArcabitAdware.Generic.D2FD503
VirITTrojan.Win32.Fakealert.BBJK
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Adware.VirusCure.AA
TrendMicro-HouseCallADW_FAKEAV
AvastWin32:MiscX-gen [PUP]
BitDefenderAdware.Generic.3134723
NANO-AntivirusTrojan.Win32.Fakealert.cdtnq
TencentMalware.Win32.Gencirc.14034c04
EmsisoftAdware.Generic.3134723 (B)
F-SecureAdware.ADWARE/Agent.290816.41
DrWebTrojan.Fakealert.18496
VIPREAdware.Generic.3134723
TrendMicroADW_FAKEAV
SophosGeneric Reputation PUA (PUA)
JiangminFraudTool.Anticare.a
WebrootW32.Malware.gen
VaristW32/FakeAlert.BZFJ-4505
AviraADWARE/Agent.290816.41
MAXmalware (ai score=99)
KingsoftWin32.Troj.Undef.a
XcitiumApplicUnwnt@#3guvym1ahm92z
MicrosoftRogue:Win32/Vakcune
GDataAdware.Generic.3134723
CynetMalicious (score: 99)
AhnLab-V3PUP/Win.Agent.R13462
McAfeeGeneric FakeAV.ck
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingRogue.Vakcune!8.CF6 (TFE:5:G79Yg8fDyHS)
YandexTrojan.GenAsa!9DKhyVxhbKY
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.2588.susgen
FortinetRiskware/VirusCure
AVGWin32:MiscX-gen [PUP]
DeepInstinctMALICIOUS

How to remove Rogue:Win32/Vakcune?

Rogue:Win32/Vakcune removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment