Malware

MSIL/Packed.CodeWall.B removal

Malware Removal

The MSIL/Packed.CodeWall.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Packed.CodeWall.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine MSIL/Packed.CodeWall.B?


File Info:

name: 98340F5EA591CD16C5F9.mlw
path: /opt/CAPEv2/storage/binaries/a6ba9c9fe9ba74387b1662526465ab75e8177e588a962e0ec9aaa0e7ad1eb4cf
crc32: B19EC7E1
md5: 98340f5ea591cd16c5f9d3a9e95641a4
sha1: 873871179f145a0e4d9d91d9aed837ae0e4e1ac6
sha256: a6ba9c9fe9ba74387b1662526465ab75e8177e588a962e0ec9aaa0e7ad1eb4cf
sha512: 63ae3683e05171ede8ed1ad571c1274b7b1be376197003c6ccb706e37688730c72565dc85016f2ffdcd76ab072069b90d2a95723359527caeb6b1ab99257d974
ssdeep: 3072:8IfeoadX9ZTuXT4XH1nuzYYwqe/U7/okpIH9aZMHD5aa:pfadX9Z8ygzYY3e/UMkp1GD5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5141998FF0CD582D26CB237C1E6452003628CD5CB1AF95B6D553BCC9BE33B309656AA
sha3_384: 2cacc69bb4b9af25c2311865bac42367dccef18030ee51b875619754eeee8212cfd7c3f7eee9ab64d367956ad4c99042
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-02-07 19:14:59

Version Info:

Translation: 0x0000 0x04b0
Comments: RPX 1.3.4399.43191
FileDescription:
FileVersion: 0.0.0.0
InternalName: 1.exe
LegalCopyright:
OriginalFilename: 1.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/Packed.CodeWall.B also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader8.49902
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.98340f5ea591cd16
McAfeeArtemis!98340F5EA591
CylanceUnsafe
ZillyaTrojan.Disfa.Win32.3592
K7AntiVirusTrojan ( 00528cb81 )
K7GWTrojan ( 00528cb81 )
Cybereasonmalicious.ea591c
BitDefenderThetaGen:NN.ZemsilF.34062.mm0@aSYtCop
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.CodeWall.B
TrendMicro-HouseCallTROJ_SPNR.3AHQ13
KasperskyHEUR:Trojan.MSIL.ShopBot.gen
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Disfa.cuimbu
AvastMSIL:GenMalicious-FX [Trj]
TencentMsil.Trojan.Disfa.Hssa
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/Generic-S
ComodoMalware@#3kf8pgi477r2r
F-SecureHeuristic.HEUR/AGEN.1118661
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.3AHQ13
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
IkarusPUA.Codewall
AviraHEUR/AGEN.1118661
MAXmalware (ai score=82)
KingsoftWin32.Troj.Disfa.p.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AA
GDataGen:Heur.MSIL.Bladabindi.1
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
YandexTrojan.Disfa!3vmNYQJBWDU
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGMSIL:GenMalicious-FX [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove MSIL/Packed.CodeWall.B?

MSIL/Packed.CodeWall.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment