Malware

About “Packed.Win32.Krap.gx” infection

Malware Removal

The Packed.Win32.Krap.gx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packed.Win32.Krap.gx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Packed.Win32.Krap.gx?


File Info:

name: 46D55033D28E256096F7.mlw
path: /opt/CAPEv2/storage/binaries/82c9b2c8cfb6faefce9cd518cf73c67f8e30b2a38fb34ce22c4c1b844105ff8a
crc32: 23007FC6
md5: 46d55033d28e256096f7506ce1f18715
sha1: eb7211b6895fb657df374dd35a041a4c8fb1c9d5
sha256: 82c9b2c8cfb6faefce9cd518cf73c67f8e30b2a38fb34ce22c4c1b844105ff8a
sha512: b302329645ca9a6a4f10c11caca3fcaedb38e4f98fe721eb5dcffda50b869de4e81b80b904bb57ae6dd19e22f5fc749804fabf725dfbd8b1a8db36071a2dba42
ssdeep: 3072:FV7VeaOY8hneuaFWAa2bZELtHulgopuhwoYnS+yl0htvJH8+d:FlgY8hne1FzBtkHunu7YJ8M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DF3BF362106E46BE4546EF015D6FC11976A3097B0D7DF12F7E86CABCA3AB2E1815338
sha3_384: fffc54840da1daf995a3c0722875caed2663908836ef61258e3eb379fa4fd0a7d7b111fa4e0a9f6ec69ffc4d73b487b3
ep_bytes: 558bec81c4e8feffffbe786800005268
timestamp: 2007-05-28 05:35:46

Version Info:

CompanyName: ЫТеЙРдНтЯшЩЯЬЦиьМЧьПЧш
FileDescription: нЧАдШбИсИЕЧгеЬУХкъхЮюЭЖШ
FileVersion: 66.92.66.97
InternalName: мяФмДюрХЭЖУпУЧчървкКЮЕЫЪаМХшЮ
LegalCopyright: 4143-4408
OriginalFilename: BqE.exe
ProductName: вэкМтЯкЖдАрЮИСртУЖхЕГВьч
ProductVersion: 66.92.66.97
Translation: 0x04b0 0x0417

Packed.Win32.Krap.gx also known as:

LionicHacktool.Win32.Krap.x!c
Elasticmalicious (high confidence)
ClamAVWin.Spyware.Zbot-1282
FireEyeGeneric.mg.46d55033d28e2560
ALYacGen:Variant.Oficla.3
CylanceUnsafe
VIPRETrojan.Win32.Nedsym.f (v)
SangforTrojan.Win32.Zbot.gen!Y
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanPSW:Win32/FakeAV.3d1c2af4
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.3d28e2
VirITTrojan.Win32.Packed.BECL
CyrenW32/Zbot.AK.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.gx
BitDefenderGen:Variant.Oficla.3
NANO-AntivirusTrojan.Win32.Zbot.bjsfs
MicroWorld-eScanGen:Variant.Oficla.3
AvastWin32:MalOb-IJ [Cryp]
TencentWin32.Packed.Krap.Pezt
Ad-AwareGen:Variant.Oficla.3
EmsisoftGen:Variant.Oficla.3 (B)
ComodoMalCrypt.Indus!@1qrzi1
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Packed.20343
ZillyaTrojan.Zbot.Win32.196026
TrendMicroBKDR_QAKBOT.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosML/PE-A + Mal/Zbot-U
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Oficla.3
JiangminTrojanSpy.Zbot.agnt
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Packed]/Win32.Krap
KingsoftWin32.Troj.Krap.gx.(kcloud)
ArcabitTrojan.Oficla.3
ZoneAlarmPacked.Win32.Krap.gx
MicrosoftPWS:Win32/Zbot.gen!Y
Acronissuspicious
McAfeePWS-Zbot.gen.aum
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Papras
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallBKDR_QAKBOT.SMC
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!Vm+EHLNRmZk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Krypt.A!tr.dldr
BitDefenderThetaAI:Packer.1FA1BDD71F
AVGWin32:MalOb-IJ [Cryp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Packed.Win32.Krap.gx?

Packed.Win32.Krap.gx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment