Trojan

Generic.Trojan.Malpack.DDS removal instruction

Malware Removal

The Generic.Trojan.Malpack.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Trojan.Malpack.DDS virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to masquerade or mimic a legitimate process or file name
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Trojan.Malpack.DDS?


File Info:

name: A81BBF0EF7DF12EC68B9.mlw
path: /opt/CAPEv2/storage/binaries/7da879d55c9c46fc81868dbeb5fd30ad65338facdbbc9a296753f9cea1863f76
crc32: 463E0D01
md5: a81bbf0ef7df12ec68b9c3cb186fe72c
sha1: 536e52b73a40bd31a7c639021fbcbbb65546f3b4
sha256: 7da879d55c9c46fc81868dbeb5fd30ad65338facdbbc9a296753f9cea1863f76
sha512: 5d024cbbad85d73c111c428299fa3bff814637b830d6ebd72484a8682018a18dae06266a24736a4fb54dc48db48970c5f74cbafa4482d64d3a6c4e2936b2a749
ssdeep: 12288:1hkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNl0D3c23:DRmJkcoQricOIQxiZY1WNlCs23
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DEF4AF21F5C68076C2B323B19E7EF76A9A3D79360336D19727C82D315EA05816B29733
sha3_384: 675af88b5be25cfdae74e584535722c109077de0f8053b8f5792fbaab4d99b763bb8c6eeeb581eff680cfdd9d6de5a0f
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Generic.Trojan.Malpack.DDS also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Strictor.104585
FireEyeGeneric.mg.a81bbf0ef7df12ec
CAT-QuickHealTrojan.AutoIt.Pistolar.A
McAfeeComame.b
MalwarebytesGeneric.Trojan.Malpack.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaWorm:Win32/Moarider.c8436c5f
K7GWTrojan ( 700000111 )
Cybereasonmalicious.ef7df1
BaiduWin32.Trojan.AutoIt.a
CyrenW32/AutoIt.AQ2.gen!Eldorado
SymantecBloodhound.Malautoit
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Malware.Autoit-6991628-0
KasperskyTrojan.Win32.Autoit.aza
BitDefenderGen:Variant.Strictor.104585
NANO-AntivirusTrojan.Win32.Autoit.fkkztg
AvastAutoIt:Agent-DP [Trj]
TencentTrojan.Win32.Agent.hab
EmsisoftGen:Variant.Strictor.104585 (B)
F-SecureTrojan.TR/AutoIt.axovq
DrWebTrojan.DownLoader9.25733
VIPREGen:Variant.Strictor.104585
TrendMicroTROJ_GEN.R002C0CDM23
McAfee-GW-EditionBehavesLike.Win32.Comame.bh
Trapminemalicious.high.ml.score
SophosMal/Sohana-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1GHRIQ4
GoogleDetected
AviraTR/AutoIt.axovq
XcitiumTrojWare.Win32.Agent.AZAB@59q48x
ArcabitTrojan.Strictor.D19889
ZoneAlarmTrojan.Win32.Autoit.aza
MicrosoftWorm:Win32/Moarider.A
CynetMalicious (score: 99)
AhnLab-V3HEUR/Fakon.mwf.X1381
ALYacGen:Variant.Strictor.104585
MAXmalware (ai score=89)
VBA32Trojan.Autoit.Wirus
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0CDM23
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
IkarusTrojan.Win32.Autoit
FortinetW32/Sohana.A!tr
AVGAutoIt:Agent-DP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Trojan.Malpack.DDS?

Generic.Trojan.Malpack.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment