Home Malware Programs Viruses HeurEngine.Vmpbad

HeurEngine.Vmpbad

Posted: June 10, 2010

Threat Metric

Ranking: 6,081
Threat Level: 8/10
Infected PCs: 3,953
First Seen: December 6, 2010
Last Seen: January 16, 2022
OS(es) Affected: Windows

HeurEngine.Vmpbad (or Packed.Vmpbad!gen1) is a malicious application that downloads other malware onto your computer. HeurEngine.Vmpbad will attempt to download and install adware, Trojans and viruses onto your computer. HeurEngine.Vmpbad also logs your typed keystrokes and sends personal data, including online banking details, to a remote hacker. HeurEngine.Vmpbad opens a huge security hole on your computer and should be removed immediately once detected.

Aliases

Generic7_c.PQX [AVG]TR/Agent.VMProtect.aaa.24 [AntiVir]UDS:DangerousObject.Multi.Generic [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]Artemis!AD363F4136AB [McAfee]Generic3_c.AUFQ [AVG]W32/Dx.VLL!tr [Fortinet]Gen.Malware.Heur [Ikarus]Trojan/Win32.Genome.gen [Antiy-AVL]Heuristic.LooksLike.Win32.SuspiciousPE.F!88 [McAfee-GW-Edition]Tool.Patcher.65 [DrWeb]Gen:Malware.Heur.0yW@bq2z78fi [BitDefender]HEUR:VirTool.Win32.Generic [Kaspersky]Win.Trojan.Agent-113 [ClamAV]Generic.dx!vll [McAfee]
More aliases (247)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to HeurEngine.Vmpbad may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria .

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\system32\drivers\keymulti.sys\keymulti.sys File name: keymulti.sys
Size: 209.92 KB (209928 bytes)
MD5: ad363f4136ab695a5ec80201e70f3bae
Detection count: 637
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\keymulti.sys\
Group: Malware file
Last Updated: January 11, 2022
%PROGRAMFILES(x86)%\Delcam\Flex\delcam.exe\delcam.exe File name: delcam.exe
Size: 2.32 MB (2321920 bytes)
MD5: 0f6a2063a89a8e9b6088819ef465d87e
Detection count: 190
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Delcam\Flex\delcam.exe\
Group: Malware file
Last Updated: January 7, 2022
E:\System Volume Information\_restore{FEA0EC40-F00D-4719-B588-D5189CD1D076}\RP9\A0002448.exe\A0002448.exe File name: A0002448.exe
Size: 5.44 MB (5441536 bytes)
MD5: 15e89aa3c21af2b16058597f1a284b3b
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: E:\System Volume Information\_restore{FEA0EC40-F00D-4719-B588-D5189CD1D076}\RP9\A0002448.exe\
Group: Malware file
Last Updated: January 16, 2022
%PROGRAMFILES%\eBoostr\EBstrSvc.exe File name: EBstrSvc.exe
Size: 340.99 KB (340992 bytes)
MD5: dd8616a55bd6619a17733d99eee5513b
Detection count: 115
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\eBoostr\
Group: Malware file
Last Updated: July 14, 2020
%PROGRAMFILES%\eBoostr\eBoostrCP.exe File name: eBoostrCP.exe
Size: 1.06 MB (1060352 bytes)
MD5: 040daf2e76c8de029d415b435d731819
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\eBoostr\
Group: Malware file
Last Updated: July 14, 2020
C:\Program Files\Reality Pump\Two Worlds II\KEYGEN.exe\KEYGEN.exe File name: KEYGEN.exe
Size: 146.94 KB (146944 bytes)
MD5: ee2895ca1022f9cdb28d65ff1b9b07de
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Reality Pump\Two Worlds II\KEYGEN.exe\
Group: Malware file
Last Updated: November 21, 2021
%TEMP%\427193.exe File name: 427193.exe
Size: 826.36 KB (826368 bytes)
MD5: 5fc79569b97d3dbf10df260f58777027
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\
Group: Malware file
Last Updated: January 8, 2013
D:\crysis 2\bin32\Crysis2.exe File name: Crysis2.exe
Size: 36.76 MB (36762112 bytes)
MD5: 8264d92139dc4120eeb0d70b546b7c55
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: D:\crysis 2\bin32\
Group: Malware file
Last Updated: January 4, 2022
%WINDIR%\svserv.exe File name: svserv.exe
Size: 198.65 KB (198656 bytes)
MD5: eed1705e1fd73033cc9d8cf16bdbb101
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\
Group: Malware file
Last Updated: December 6, 2010
%APPDATA%\archsoft\archstart.exe File name: archstart.exe
Size: 1.45 MB (1458176 bytes)
MD5: 36636bff69282fe555b96e139b54af3e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\archsoft\
Group: Malware file
Last Updated: June 20, 2011
%APPDATA%\archsoft\archivestart.exe File name: archivestart.exe
Size: 1.45 MB (1454080 bytes)
MD5: 0740566ae2e8c48b152d282de4f1bafa
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\archsoft\
Group: Malware file
Last Updated: December 3, 2012
%APPDATA%\archsoft\arstart.exe File name: arstart.exe
Size: 1.44 MB (1445888 bytes)
MD5: cf1ca8cc9fb7dd37d01e8a0f2a1ac876
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\archsoft\
Group: Malware file
Last Updated: July 4, 2011
%APPDATA%\archsoft\arustart.exe File name: arustart.exe
Size: 1.42 MB (1421312 bytes)
MD5: 9b9e4fa093b615340cb4770fe37f347b
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\archsoft\
Group: Malware file
Last Updated: July 18, 2011

More files