Trojan

What is “ASProtect.Trojan.MalPack.DDS”?

Malware Removal

The ASProtect.Trojan.MalPack.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ASProtect.Trojan.MalPack.DDS virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine ASProtect.Trojan.MalPack.DDS?


File Info:

name: 67EE3CAD96ABC4342E39.mlw
path: /opt/CAPEv2/storage/binaries/3eb0b7ff4727cfda5f36816185408f1d7d26a2d0cc0f058161265bca955f3634
crc32: C21470EB
md5: 67ee3cad96abc4342e397458a67b9672
sha1: d8da3c4a644952285f9f151f312948ea8fec42c2
sha256: 3eb0b7ff4727cfda5f36816185408f1d7d26a2d0cc0f058161265bca955f3634
sha512: 8b1a6afb8ed460ef6b5b5e2761d25d4551971dc31a11575f9a909cf75e72a5602a2b4cc609c67d11932e3d2ec5adab28c97d5cfb1472c8879acabb817e6af580
ssdeep: 3072:67v5I31Wr7Rm2pfna1vES43tkM3wQPyfrdHDOilQAM0csASL5Nqg3JnIZ:69g1WrkRES4Z3wJxDJqh0cs3UIN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A441287CDD06ADAE8BB7F3053E90F6D13B3FF526981B5020856B0891EF35621C69693
sha3_384: bf70cd7be74cfa227c2fd34cb4d6175c5e677f977bbcf3a3933b76ffae212b3a03b6412f0448cb7e3d1353ee12bfba97
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0809 0x04e4

ASProtect.Trojan.MalPack.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.4!c
DrWebBackDoor.Pigeon.64423
FireEyeGeneric.mg.67ee3cad96abc434
SkyhighBehavesLike.Win32.Dropper.dc
MalwarebytesASProtect.Trojan.MalPack.DDS
SangforTrojan.Win32.Agent.Vbkf
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderThetaGen:NN.ZelphiF.36792.pO0baKXFcAej
VirITBackdoor.Win32.Hupigon.RQKE
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Trojan.Zusy-9785366-0
NANO-AntivirusTrojan.Win32.Hupigon.bbmita
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1324299
ZillyaBackdoor.Hupigon.Win32.126200
IkarusTrojan.Backdoor.Hupigon5
JiangminBackdoor/Hupigon.bvac
GoogleDetected
AviraHEUR/AGEN.1324299
VaristW32/Trojan.BAQT-0462
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Script/Phonzy.A!ml
CynetMalicious (score: 100)
McAfeeArtemis!67EE3CAD96AB
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Pigeon
TrendMicro-HouseCallTROJ_GEN.R002V01JJ23
TencentMalware.Win32.Gencirc.13c029e8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware [Misc]
Cybereasonmalicious.a64495
AvastFileRepMalware [Misc]

How to remove ASProtect.Trojan.MalPack.DDS?

ASProtect.Trojan.MalPack.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment