Malware

About “Packed.Win32.Katusha.o” infection

Malware Removal

The Packed.Win32.Katusha.o is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packed.Win32.Katusha.o virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Packed.Win32.Katusha.o?


File Info:

crc32: F79A1C9D
md5: a3bb8eb3f44907ffdb8ba078ec2ca996
name: A3BB8EB3F44907FFDB8BA078EC2CA996.mlw
sha1: 8adfadef71dd547a0486e474dcbfcc488bea6bce
sha256: cfd643a77ad0d39d3c6c521409ca569057ab32e1481eb37af4281c09bfb4006c
sha512: 2c1fd871c9a830c2065b5a0a2563511da157c9e09cb26994c2f0336c12c8bdabff9e8cc1fb6731b167d912baedcb83a6fd4fc9e857990c9056a5563bfac897c5
ssdeep: 1536:nPgHIDR9h4FHep1yI3MtaWVyIqYhxiClVmyBYp/zSBV/RRhVGflrhDLb0:nPgsRf4RIH36qqPCg5RhGldLb0
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Packed.Win32.Katusha.o also known as:

K7AntiVirusTrojan ( 004f99a61 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Katusha.e13e9f85
K7GWTrojan ( 004f99a61 )
Cybereasonmalicious.3f4490
CyrenW32/S-b5a1ff1e!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
APEXMalicious
AvastWin32:Malware-gen
KasperskyPacked.Win32.Katusha.o
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Katusha.evkorq
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentMalware.Win32.Gencirc.10b6a45e
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
ComodoMalware@#2elikdmw6zgxq
BitDefenderThetaGen:NN.ZexaF.34628.fy0@aWeKVchQ
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.PUPXER.nh
FireEyeGeneric.mg.a3bb8eb3f44907ff
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminPacked.Katusha.cicf
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Ransom.CryptXXX.1
AegisLabHacktool.Win32.Katusha.x!c
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188553
Acronissuspicious
McAfeeRansomware-GJA!A3BB8EB3F449
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.929094131
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingRansom.Tovicrypt!8.9F4B (CLOUD)
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Ransom.Tovicrypt.HxQBEpsA

How to remove Packed.Win32.Katusha.o?

Packed.Win32.Katusha.o removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment