Trojan

What is “Trojan.MalPack.NSPack”?

Malware Removal

The Trojan.MalPack.NSPack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MalPack.NSPack virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Anomalous binary characteristics

Related domains:

cdn.leafletjs.com
dev.virtualearth.net
c.tile.openstreetmap.org
a.tile.openstreetmap.org
b.tile.openstreetmap.org
www.registratorviewer.com
ww1.registratorviewer.com
i4.cdn-image.com
i3.cdn-image.com
i1.cdn-image.com
i2.cdn-image.com

How to determine Trojan.MalPack.NSPack?


File Info:

crc32: 20B3AA25
md5: 412ca838f23e8d28de907f705b933055
name: VANTRUE-CAM-PLAYER.exe
sha1: e181d64363570f8eb76995004aa9d72cf89a204b
sha256: b7794cbf71069b6760caf140fc38aa6ca98dfd0fc593974461acf9a66f18ae28
sha512: 6dd36ad956d102f1cf2fc290fbbb728907e753115dcd5e87f8f2e0f00a4f4e0f39b6cafbc728e98a4994e47866e7a31d14ef4278263e9c507425bccd9c9d738d
ssdeep: 24576:eCor+zw4oaxgisvbU3QAgHqtHLKaYX+EEs8FXxaDrWphXzvYz:eCNNoiWoAAg+YXVkoAhXsz
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: VANTRUE
InternalName: VANTRUE CAM PLAYER
FileVersion: 3.0.1.1
CompanyName: VANTRUE
LegalTrademarks: VANTRUE
Comments: VANTRUE CAM PLAYER
ProductName: VANTRUE CAM PLAYER
ProductVersion: 3.0
FileDescription: VANTRUE CAM PLAYER
OriginalFilename: VANTRUE CAM PLAYER.exe
Translation: 0x0809 0x04b0

Trojan.MalPack.NSPack also known as:

MicroWorld-eScanTrojan.Generic.17930088
FireEyeGeneric.mg.412ca838f23e8d28
CAT-QuickHealTrojan.Multi
McAfeeArtemis!412CA838F23E
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 005257651 )
BitDefenderTrojan.Generic.17930088
K7GWTrojan ( 005257651 )
Cybereasonmalicious.8f23e8
Invinceaheuristic
F-ProtW32/Heuristic-162!Eldorado
APEXMalicious
GDataTrojan.Generic.17930088
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Application/Generic.048e80ef
NANO-AntivirusTrojan.Win32.NSPI.ekxsgt
Endgamemalicious (high confidence)
SophosMal/Packer
ComodoTrojWare.Win32.Trojan.NSPM.~gen@20n73t
F-SecureTrojan.TR/Crypt.NSPI.Gen
DrWebTrojan.DownLoader22.61034
TrendMicroTROJ_GEN.R002C0RCG19
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.17930088 (B)
IkarusTrojan.Crypt
CyrenW32/Heuristic-162!Eldorado
WebrootW32.Backdoor.Hupigon
AviraTR/Crypt.NSPI.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
ZoneAlarmUDS:DangerousObject.Multi.Generic
Acronissuspicious
ALYacTrojan.Generic.17930088
Ad-AwareTrojan.Generic.17930088
MalwarebytesTrojan.MalPack.NSPack
TrendMicro-HouseCallTROJ_GEN.R002C0RCG19
TencentWin32.Trojan.Crypt.Oyym
YandexTrojan.NSPI!BDZvDRLuBjA
SentinelOneDFI – Suspicious PE
eGambitGeneric.Malware
FortinetPossibleThreat
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.MalPack.NSPack?

Trojan.MalPack.NSPack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment