Trojan

Trojan.MalPack.TCL.Generic (file analysis)

Malware Removal

The Trojan.MalPack.TCL.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MalPack.TCL.Generic virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.MalPack.TCL.Generic?


File Info:

crc32: 03CF5905
md5: 028428b987f3d98091670216752c84f1
name: 028428B987F3D98091670216752C84F1.mlw
sha1: 40c9a683d22410ac9214ecee1eec6d31c6a97d91
sha256: 3cd2dc952a6d530e3e7f69ae8f0dc94453f89dc86305220a533ce193463ba79e
sha512: bc55863e192bd8c5f455034c4ff264bebda2119aafcfc474613dd6073c77f0ec098a7c77189148df555dff5e4cc9eeb7445439cbf4c78082f3c0a01f6354ae2c
ssdeep: 24576:RAHnh+eWsN3skA4RV1Hom2KXMmHaeyyMKfrhZpZWlYWz5:oh+ZkldoPK8YaekkdZVi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Cw5FzvBFmDVwGn587PHefZa4pd1Nrq6R9 Technology Co. Ltd., All rights reserved.
InternalName: wscript.exe
FileVersion: 6.9.6.6
CompanyName: Windows IPsec SPD Client DLL
Comments: RFVLaf3CnfaNtyDc6xe3cvbAge56XtRx8V6LcPwOqc1gPwyg43ZMRtsBtHq9BRbOadOx1cPlp
ProductVersion: 6.9.6.6
FileDescription: SHCORE
OriginalFilename: wscript.exe
Translation: 0x0809 0x04b0

Trojan.MalPack.TCL.Generic also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
LionicHacktool.Win32.Gamehack.3!e
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.AutoIT.17nv0@aKBVBIgi
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/CoinMiner.fdb8d7cd
K7GWTrojan ( 700000111 )
Cybereasonmalicious.987f3d
ESET-NOD32a variant of Win32/Packed.AutoIt.JH
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Autoit.absdd
BitDefenderGen:Trojan.Heur.AutoIT.17nv0@aKBVBIgi
NANO-AntivirusTrojan.Win32.Autoit.fvdyrm
MicroWorld-eScanGen:Trojan.Heur.AutoIT.17nv0@aKBVBIgi
TencentWin32.Trojan.Autoit.Duq
Ad-AwareGen:Trojan.Heur.AutoIT.17nv0@aKBVBIgi
SophosMal/Generic-S
ComodoMalware@#2oxu7yv57ysed
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.028428b987f3d980
EmsisoftGen:Trojan.Heur.AutoIT.17nv0@aKBVBIgi (B)
AviraHEUR/AGEN.1100133
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Heur.AutoIT.ED6188
GDataGen:Trojan.Heur.AutoIT.17nv0@aKBVBIgi
McAfeeArtemis!028428B987F3
VBA32Trojan.AutoIt
MalwarebytesTrojan.MalPack.TCL.Generic
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
IkarusTrojan.Win32.CoinMiner
MaxSecureTrojan.Malware.11914803.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.MalPack.TCL.Generic?

Trojan.MalPack.TCL.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment