Malware

Win32/Ipamor malicious file

Malware Removal

The Win32/Ipamor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Ipamor virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Win32/Ipamor?


File Info:

name: A200A24AD46233E688D5.mlw
path: /opt/CAPEv2/storage/binaries/f01eeaede2561eeb1023a9dbdf11561a0ec0644bca8a44dff17ca9184497f20f
crc32: 5136BDAA
md5: a200a24ad46233e688d573148d6736d2
sha1: 0bd6f4fdf0ffa990b42a191dca77295fa6df393d
sha256: f01eeaede2561eeb1023a9dbdf11561a0ec0644bca8a44dff17ca9184497f20f
sha512: 9dc7179573138981c7b138ca0cd4a0ebf222e998509c8c23a576af39b9df899fa67a27402e378149c665c4691fcf6b408c5df9f917ed7ce68f095b102d081d14
ssdeep: 12288:phJ6yfBSTOYREAUCztyBi0tyLp8rlA3s5/z:phJ6yfYTOYKAzB6rlge/z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9C46C017BF98539F6B70E718EB58A66A9B2FD615C10CD0F13801A1CD576D81CEB2F2A
sha3_384: 2b0a4472786eaba26d8ad020706cec14dd3db424f8073a1770689490ca8627b7a2a0673ad3791508d24283e31d90e39f
ep_bytes: 558bec6aff6820b2400068ac6f400064
timestamp: 2002-06-27 08:27:05

Version Info:

0: [No Data]

Win32/Ipamor also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.66279085
FireEyeGeneric.mg.a200a24ad46233e6
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeW32/Ipamor.a
MalwarebytesIpamor.Trojan.RAT.DDS
ZillyaVirus.Ipamor.Win32.4
SangforVirus.Win32.Save.a
K7AntiVirusVirus ( 0040f5921 )
K7GWVirus ( 0040f5921 )
Cybereasonmalicious.ad4623
CyrenW32/HLLP.Ipamor
SymantecW32.HLLP.Ipamor
tehtrisGeneric.Malware
ESET-NOD32Win32/Ipamor
CynetMalicious (score: 100)
ClamAVWin.Trojan.Iparm-1
KasperskyVirus.Win32.Ipamor.a
BitDefenderTrojan.GenericKD.66279085
NANO-AntivirusVirus.Win32.Ipamor.cmay
AvastWin32:Ipamor
TencentVirus.Win32.Viking.aak
EmsisoftTrojan.GenericKD.66279085 (B)
F-SecureTrojan.TR/Agent.arue
DrWebWin32.HLLP.Iparmor
VIPRETrojan.GenericKD.66279085
TrendMicroPE_IPAMOR.E-O
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SophosW32/Ipamor-B
SentinelOneStatic AI – Suspicious PE
GDataWin32.Virus.Ipamor-Main.A
JiangminWin32/Ipamor
AviraTR/Agent.arue
MAXmalware (ai score=81)
Antiy-AVLTrojan[Banker]/Win32.Banbra
XcitiumWin32.Ipamor@2036
ArcabitTrojan.Generic.D3F356AD
ViRobotWin32.Ipamor.A
ZoneAlarmVirus.Win32.Ipamor.a
MicrosoftVirus:Win32/Ipamor.A
GoogleDetected
AhnLab-V3Win32/Ipamor.D.X1356
VBA32Virus.Ipamor.8109
ALYacTrojan.GenericKD.66279085
Cylanceunsafe
TrendMicro-HouseCallPE_IPAMOR.E-O
RisingTrojan.IpMbd (CLASSIC)
YandexTrojan.GenAsa!qp+sKG55Fu8
IkarusVirus.Win32.Ipamor.A
MaxSecureVirus.Ipamor.Gen
FortinetW32/Ipamor.D
BitDefenderThetaAI:Packer.8955577D1F
AVGWin32:Ipamor
PandaW32/Qril.B
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Ipamor?

Win32/Ipamor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment