Malware

Win32:MalPack-B [Trj] removal instruction

Malware Removal

The Win32:MalPack-B [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:MalPack-B [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Win32:MalPack-B [Trj]?


File Info:

name: DBDC054010C95B0283BE.mlw
path: /opt/CAPEv2/storage/binaries/2bae86de96b7b21b50ecfaec7ae7d070df36077e68942097f1726601a4e8d4bb
crc32: AB0E5228
md5: dbdc054010c95b0283be4afc979c23e8
sha1: 0a091a1594bd132244a97f696e0c4ec7488b410e
sha256: 2bae86de96b7b21b50ecfaec7ae7d070df36077e68942097f1726601a4e8d4bb
sha512: 96e48d26fa456e50f4bbbbabf5b11239abd4768268de4286f01a1b60ff6befc8b9e50d9a88bc74e112187befd4f0729306b31f712c38e0b91263912ddca5f83c
ssdeep: 1536:zku1AFjcb8tHBmP3S6lXUXqaIUL/R8dPtSAV8bcYUrd3gaDV6WP3ueWWWhWWWEWs:DCtcbmhm66lU6aNLatSAGY9DL3RWWWhN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B983D0813F70B1D9F6A907701D8AC6B3DC5D9862E82DE4BB4439F55EA6F03C95036239
sha3_384: 8057aa01c32d50d587caba35a81f25b4aca5390974dd18b7cdf42c9dfa592b1c1aa740e3ad98b675be7f4839530c711d
ep_bytes: 558bec6aff680470400068a016400064
timestamp: 2011-03-04 05:11:40

Version Info:

CompanyName: injyfie Eegl
FileDescription: imis
FileVersion: 2.2.800.4400
InternalName: imahoo
LegalCopyright: underyent © dixi 1992-2011
OriginalFilename: noniv.exe
ProductName: Reqles
ProductVersion: 2.2.800.4400
Translation: 0x0409 0x04b0

Win32:MalPack-B [Trj] also known as:

BkavW32.MassiveUsbD.Worm
MicroWorld-eScanGen:Heur.Mint.Zard.24
FireEyeGeneric.mg.dbdc054010c95b02
CAT-QuickHealTrojan.Rimecud.U
McAfeePWS-Zbot.gen.aqm
CylanceUnsafe
VIPREGen:Heur.Mint.Zard.24
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 700000161 )
K7GWTrojan ( 700000161 )
Cybereasonmalicious.010c95
CyrenW32/Rimecud.AM.gen!Eldorado
SymantecW32.Pilleuz!gen36
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AIRI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.24
NANO-AntivirusTrojan.Win32.Yakes.dchgtg
AvastWin32:MalPack-B [Trj]
TencentWin32.Trojan.Yakes.Wvku
Ad-AwareGen:Heur.Mint.Zard.24
EmsisoftGen:Heur.Mint.Zard.24 (B)
ComodoTrojWare.Win32.Kryptik.AJGK@4pzgon
ZillyaTrojan.Yakes.Win32.21920
TrendMicroTROJ_RIMECUD.SMX
McAfee-GW-EditionPWS-Zbot.gen.aqm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/HkMain-CT
IkarusVirus.Win32.Cryptor
GDataGen:Heur.Mint.Zard.24
JiangminPack.Mal.AntiVM.a
GoogleDetected
AviraTR/Rimecud.J.1
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.24F
MicrosoftTrojan:Win32/Rimecud.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Palevo.R32247
Acronissuspicious
VBA32BScope.Worm.Palevo.3072
ALYacGen:Heur.Mint.Zard.24
TrendMicro-HouseCallTROJ_RIMECUD.SMX
RisingTrojan.Generic@AI.100 (RDML:G9RUfaJtxLq9qtnxd2gCBg)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EQMA!tr
BitDefenderThetaGen:NN.ZexaF.34592.fq0@aO0tPMmi
AVGWin32:MalPack-B [Trj]
PandaTrj/Rimecud.f
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32:MalPack-B [Trj]?

Win32:MalPack-B [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment