Malware

What is “Packed.Win32.Krap.hm”?

Malware Removal

The Packed.Win32.Krap.hm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packed.Win32.Krap.hm virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Packed.Win32.Krap.hm?


File Info:

crc32: 2E4F5622
md5: fcaa38a6fdc673584dcbb74ef6fe70f2
name: FCAA38A6FDC673584DCBB74EF6FE70F2.mlw
sha1: 19aafcd6ea700210b973a3a6868d7e90f9cd1cf4
sha256: fbebaa19ad2bdb019d6ab6ddabafc075b902f17462acb15011264f897e932e35
sha512: f22c785749d705fac922bb9ac037e5955abebfbc4f3a936d4554e23e0b3ce0007597ac4d816eb81ecae5ca50c39a16e7b8d59ec1834dfdc40ebba781a9b5fae8
ssdeep: 1536:p+hzRsibKplyXTq8OGRnsPFG+RODTb7MXL5uXZnzECye9PcIM:MROzoTq0+RO7IwnYB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: 2528-6
InternalName: x444x436x437x440x44ex43ax448x44dx449
FileVersion: 106.42.73
CompanyName: SOFTWIN S
ProductName: x43bx44ex437x430x43dx445
ProductVersion: 106.4
FileDescription: BitDefen
OriginalFilename: nedwp
Translation: 0x0409 0x04b0

Packed.Win32.Krap.hm also known as:

MicroWorld-eScanWin32.Virtob.Gen.12
nProtectVirus/W32.Virut.Gen
CMCVirus.Win32.Virut.1!O
CAT-QuickHealW32.Virut.G
MalwarebytesTrojan.Zbot
K7AntiVirusTrojan ( 00386dc51 )
K7GWTrojan ( 00386dc51 )
TheHackerW32/Virtob.Gen(F)
BaiduWin32.Virus.Virut.gen
CyrenW32/Ramnit.UNAX-1410
SymantecW32.Virut.CF
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallBKDR_QAKBOT.SMC
AvastWin32:Virtu-A
ClamAVWin.Trojan.Generic-53
KasperskyPacked.Win32.Krap.hm
BitDefenderWin32.Virtob.Gen.12
NANO-AntivirusVirus.Win32.Virut.hpeg
ViRobotWin32.Virut.Gen.C[h]
Ad-AwareWin32.Virtob.Gen.12
SophosW32/Scribble-B
ComodoVirus.Win32.Virut.Ce
F-SecureWin32.Virtob.Gen.12
DrWebWin32.Virut.56
VIPREVirus.Win32.Virut.ce (v)
TrendMicroBKDR_QAKBOT.SMC
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lc
EmsisoftWin32.Virtob.Gen.12 (B)
F-ProtW32/Ramnit.X
JiangminWin32/Virut.bn
AviraW32/Virut.Gen
Antiy-AVLVirus/Win32.Virut.ce
KingsoftWin32.Virut.nd.53248
MicrosoftVirus:Win32/Virut.BN
ArcabitWin32.Virtob.Gen.12
AegisLabPacker.W32.Krap.hm!c
GDataWin32.Virtob.Gen.12
AhnLab-V3Win32/Virut.F
McAfeePWS-Zbot.gen.pq
AVwareVirus.Win32.Virut.ce (v)
VBA32Virus.Virut.06
ZonerTrojanDownloader.Zbot
TencentWin32.Virus.Virut.Egog
YandexWin32.Virut.Y.Gen
IkarusPacker.Win32.Krap
FortinetW32/Virut.CE.gen
AVGPSW.Generic12.AMWG
PandaW32/Sality.AO
Qihoo-360Win32/Trojan.3d2

How to remove Packed.Win32.Krap.hm?

Packed.Win32.Krap.hm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment