Malware

Packed.Win32.Krap.ag removal instruction

Malware Removal

The Packed.Win32.Krap.ag is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packed.Win32.Krap.ag virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Harvests information related to installed mail clients

How to determine Packed.Win32.Krap.ag?


File Info:

name: 6D498DBD9CDF93A2AB4A.mlw
path: /opt/CAPEv2/storage/binaries/ec7d9f11942015c2775f374993b0d254a228bddaea1e03e37c6803010a1f114d
crc32: EABB943C
md5: 6d498dbd9cdf93a2ab4ae7645f3f2073
sha1: 0db17b04ef92b322f370451a1c8a00985eebd44f
sha256: ec7d9f11942015c2775f374993b0d254a228bddaea1e03e37c6803010a1f114d
sha512: 5f9e4de5b7f586bfc73faad1d4be5e929f660a0c44bf35614a2dbd382a38bb57bf7ceddeec7cd7fdda0bfce1cd5c286c69d75aaa8676f9235f049203c3b1d851
ssdeep: 768:g84DD+qqcnK5gSoNPsZgXZI5aHkUpdI8:g84DD+qrKIp+gNZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193035AFC3A549B2AD99ACE327FAD0A446FF02EDF575889EC452BD150DD830E8E531902
sha3_384: d1e2cd23f32c4d8e8ce21da03afdd5a73d254cdd7404c890f311eacecd11a2465cafd80fe1dcacf019c2267c3eb98637
ep_bytes: fcfcfcfcb8308b4000ffe0bddcba530f
timestamp: 2002-08-30 14:18:48

Version Info:

0: [No Data]

Packed.Win32.Krap.ag also known as:

CyrenCloudW32/Gigex.A.gen!Eldorado
BkavW32.AIDetectMalware
LionicHacktool.Win32.Krap.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.GJMePfPk!16g.B31FF682
FireEyeGeneric.mg.6d498dbd9cdf93a2
McAfeeW32/Gink@MM
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Malware.GJMePfPk!16g.B31FF682
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005581461 )
AlibabaWorm:Win32/Gigex.4d00025f
K7GWTrojan ( 005581461 )
Cybereasonmalicious.d9cdf9
CyrenW32/Gigex.A.gen!Eldorado
SymantecW32.Gink.Worm
ESET-NOD32Win32/Gigex.A
APEXMalicious
KasperskyPacked.Win32.Krap.ag
BitDefenderGeneric.Malware.GJMePfPk!16g.B31FF682
AvastWin32:Evo-gen [Trj]
TencentEmail-Worm.Win32.Gigex.ha
EmsisoftGeneric.Malware.GJMePfPk!16g.B31FF682 (B)
DrWebWin32.HLLM.Gigu.24608
ZillyaWorm.Gigex.Win32.17941
TrendMicroWORM_UGIG.B
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.high.ml.score
SophosW32/Gigex-A
SentinelOneStatic AI – Malicious PE
GDataGeneric.Malware.GJMePfPk!16g.B31FF682
GoogleDetected
AviraWORM/Rbot.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan[Packed]/Win32.Krap
XcitiumWorm.Win32.Gigex.A@8f3nxw
ArcabitGeneric.Malware.GJMePfPk!16g.B31FF682
ZoneAlarmPacked.Win32.Krap.ag
MicrosoftTrojan:Win32/Vindor!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.HDC.R476052
Acronissuspicious
VBA32Packed.Krap
ALYacGeneric.Malware.GJMePfPk!16g.B31FF682
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_UGIG.B
RisingWorm.Gigex!8.5D2D (TFE:5:yC7tUjuCPuC)
YandexTrojan.GenAsa!ei8CZizcGto
IkarusWorm.Win32.Gigex
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gigex.A@mm
BitDefenderThetaAI:FileInfector.6541C4AD10
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Packed.Win32.Krap.ag?

Packed.Win32.Krap.ag removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment