Virus

Virus:Win32/Viking.MP removal instruction

Malware Removal

The Virus:Win32/Viking.MP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Viking.MP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Virus:Win32/Viking.MP?


File Info:

name: 70C9B29CFE9A83444F69.mlw
path: /opt/CAPEv2/storage/binaries/fe88a7e0d5813ef65ea86e0fe6274ba7864f7b90c7f458f6a6a6bdfa8be3f72b
crc32: B9622C83
md5: 70c9b29cfe9a83444f69585dd3063174
sha1: 6618b78eae98a7d24f89b4e8590ad10748338158
sha256: fe88a7e0d5813ef65ea86e0fe6274ba7864f7b90c7f458f6a6a6bdfa8be3f72b
sha512: 7b8800cbb40736c33b555bfdb89f4b9332a3eccf466429145942711c7690e76e8179dac79f8faf7051f5fce8ec4d12758c441de23d3a53d42be3de164826c074
ssdeep: 12288:JDb22DShTEn+PfGR+avuZ3VdKN0BlI1z5nECe:ZK2eTEn4GR+avulGN0BlIdqCe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190D47C46635504B5D077D238C7734BE2EB7A7C115721D34E03A8A7AA5F2B390BD3AB22
sha3_384: aa28923a94cbd4bdbe43a8d040063d998181850aef106c45a226e4b617e1c5e17a0be4dec4b61051e6a0061018533d4b
ep_bytes: 60be00a042008dbe0070fdffc78708d7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virus:Win32/Viking.MP also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.CGVL
FireEyeGeneric.mg.70c9b29cfe9a8344
CAT-QuickHealTrojan.GenericIH.S24070444
ALYacTrojan.Agent.CGVL
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.cfe9a8
BaiduWin32.Trojan-PSW.OLGames.be
CyrenW32/Legendmir.XJFG-4309
SymantecW32.HLLP.Philis
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/PSW.Legendmir.OA
APEXMalicious
ClamAVWin.Trojan.Lmir-24
KasperskyTrojan-GameThief.Win32.Lmir.oa
BitDefenderTrojan.Agent.CGVL
NANO-AntivirusTrojan.Win32.Lmir.dxaowj
AvastWin32:Delf-AFC [Trj]
TencentVirus.Win32.Syphilis.a
Ad-AwareTrojan.Agent.CGVL
TACHYONVirus/W32.Philis
EmsisoftTrojan.Agent.CGVL (B)
ComodoTrojWare.Win32.PSW.Legendmir.OA@2lge
DrWebTrojan.Siggen3.61405
ZillyaTrojan.Lmir.Win32.762
TrendMicroPE_LEGMIR.B
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
SophosML/PE-A + W32/LegMir-BM
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.LMir.ec
AviraW32/PSW.Lmir.oa
MicrosoftVirus:Win32/Viking.MP
ViRobotTrojan.Win32.PSWLmir.84992.B
ZoneAlarmHEUR:Virus.Win32.Infector
GDataTrojan.Agent.CGVL
CynetMalicious (score: 100)
AhnLab-V3Win32/Lemir.212992
Acronissuspicious
McAfeePWS-CangKu
MAXmalware (ai score=89)
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.2382208213
TrendMicro-HouseCallPE_LEGMIR.B
RisingTrojan.PSW.Qiji.s (RDMK:cmRtazrfSMojAj7KfVdk1ue1EpoQ)
IkarusTrojan-PWS.Win32.Lmir.mw
MaxSecureTrojan-GameThief.Lmir.OA
FortinetW32/Lmir.7128!tr
BitDefenderThetaAI:Packer.C6B1CB211F
AVGWin32:Delf-AFC [Trj]
PandaW32/Legmir.J
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Virus:Win32/Viking.MP?

Virus:Win32/Viking.MP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment