Virus

Virus:Win32/Vampiro.A malicious file

Malware Removal

The Virus:Win32/Vampiro.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Vampiro.A virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Accessed credential storage registry keys
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Vampiro.A?


File Info:

name: 747FA4E1293417D9E150.mlw
path: /opt/CAPEv2/storage/binaries/4a636935a90fa6140411a0a2f84f82ce3deeffdab17516c5db177d61dbe33f56
crc32: BE9FCB8F
md5: 747fa4e1293417d9e150ae0111ad0885
sha1: f7735e6d6be33554e5d175f5d28b72f71ae21f3b
sha256: 4a636935a90fa6140411a0a2f84f82ce3deeffdab17516c5db177d61dbe33f56
sha512: e0c5c82489de183ae740a98c70e381e657a7c23251d139fdf4356b6f1f38449441de8f4b848d9c7997481db3559df438409af0a166a4c11a76aa399337f2beb5
ssdeep: 1536:mj3EgPvGx8aHa3CnJwfk+eYYw2fUuLxg14IJwWMYpt0Sgw:mDEg3c/630ceYYw0UuLxg14IJwWMetH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1857307127BED11A2F2F27B3058BA27344A3BBC763A3AD25F4714C4694C36751EA24727
sha3_384: 284eec45cae6274745e1fc3fd7f3348f462eb35033fa258680f2c75e72c6516c4b1e7f2235acd63beb12b75f839ad3a9
ep_bytes: 558bec6aff680090400068587e400064
timestamp: 2006-01-26 19:35:16

Version Info:

CompanyName: Agere Systems
FileDescription: Agrsmdel
FileVersion: 1.70
InternalName: Agrsmdel
LegalCopyright: Copyright ©Agere Systems 1998-2004
OriginalFilename: agrsmdel.exe
ProductName: Agrsmdel
ProductVersion: 1.70
Translation: 0x0409 0x04b0

Virus:Win32/Vampiro.A also known as:

BkavW32.Common.D0C584D1
LionicVirus.Win32.Vampiro.n!c
AVGWin32:Antares [Inf]
MicroWorld-eScanWin32.Vampiro.B
FireEyeWin32.Vampiro.B
CAT-QuickHealW32.Vampiro.B
SkyhighBehavesLike.Win32.Infected.lm
McAfeeW32/Antares.a
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.Genome.Win32.93413
SangforVirus.Win32.Vampiro.Vbfj
K7AntiVirusTrojan ( 004ca3d51 )
AlibabaVirus:Win32/Vampiro.85a5e2e8
K7GWTrojan ( 004ca3d51 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:FileInfector.D00FF4660F
SymantecW32.Vampiro.A
Elasticmalicious (high confidence)
ESET-NOD32Win32/Antar
APEXMalicious
AvastWin32:Antares [Inf]
ClamAVWin.Trojan.Cholera-3
KasperskyVirus.Win32.Vampiro.c
BitDefenderWin32.Vampiro.B
NANO-AntivirusVirus.Win32.Vampiro.bdoxs
TencentVirus.Win32.Vampiro.a
EmsisoftWin32.Vampiro.B (B)
F-SecureMalware.W32/Vampiro.B
DrWebWin32.Antares.1
VIPREWin32.Vampiro.B
TrendMicroCryp_Vampiro
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminWin32/Vampiro.a
VaristW32/Vampiro.A
AviraW32/Vampiro.B
MAXmalware (ai score=90)
KingsoftWin32.Sality.G.122880
MicrosoftVirus:Win32/Vampiro.A
XcitiumVirus.Win32.Vampiro.~B@1pwxlv
ArcabitWin32.Vampiro.B
ZoneAlarmVirus.Win32.Vampiro.c
GDataWin32.Vampiro.B
GoogleDetected
AhnLab-V3Win32/Vampiro
VBA32Virus.Win32.Antar
ALYacWin32.Vampiro.B
Cylanceunsafe
PandaW32/Antares.A
TrendMicro-HouseCallCryp_Vampiro
RisingPacker.Win32.Agent.m (CLASSIC)
IkarusVirus.Win32.Vitru
MaxSecureVirus.Vampiro.Gen
FortinetW32/Antares.A
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Antar

How to remove Virus:Win32/Vampiro.A?

Virus:Win32/Vampiro.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment