Malware

UDS:Packed.Win32.Katusha removal guide

Malware Removal

The UDS:Packed.Win32.Katusha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Packed.Win32.Katusha virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine UDS:Packed.Win32.Katusha?


File Info:

crc32: FAC30C50
md5: a4ad06645f9899377b2d6dcaac9aeb35
name: A4AD06645F9899377B2D6DCAAC9AEB35.mlw
sha1: f9c3517ed9c8b38958a90ea986a8f12f9e8dc6dd
sha256: 266257468b5706973fa27732513324cca56655aa0b19b9d7f9bf6be575639e67
sha512: 901eaa8bde3bf005f10517e78105a4c96c6238d5740fb2218afd088f9941fc322fb48be236965bf915502aeb2265c57567f92e4755aa4ae33a7c43a89d08ab93
ssdeep: 12288:IvoeVhZtBVIjTnF6V/Ov+9//nNLo/QZrA1aYv1h+rz0nS:RTF6guNqQZrAd15nS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

UDS:Packed.Win32.Katusha also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005262301 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2669
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacApplication.Bundler.ICLoader.5.Gen
CylanceUnsafe
ZillyaAdware.Generic.Win32.73594
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Katusha.6cd93de4
K7GWTrojan ( 005262301 )
Cybereasonmalicious.45f989
CyrenW32/S-0c350d20!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GCUN
APEXMalicious
AvastWin32:AdwareSig [Adw]
ClamAVWin.Packed.Icloader-6952325-0
KasperskyUDS:Packed.Win32.Katusha.gen
BitDefenderApplication.Bundler.ICLoader.5.Gen
NANO-AntivirusTrojan.Win32.InstallCube.exofsn
MicroWorld-eScanApplication.Bundler.ICLoader.5.Gen
TencentMalware.Win32.Gencirc.10c8a9e5
Ad-AwareApplication.Bundler.ICLoader.5.Gen
SophosGeneric PUA PJ (PUA)
ComodoApplication.Win32.ICLoader.GD@7ia67x
McAfee-GW-EditionGenericRXEO-DM!A4AD06645F98
FireEyeGeneric.mg.a4ad06645f989937
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.cag
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2457201
MicrosoftPUADlManager:Win32/InstallCube
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataApplication.Bundler.ICLoader.5.Gen
AhnLab-V3PUP/Win32.ICLoader.R219533
Acronissuspicious
McAfeeGenericRXEO-DM!A4AD06645F98
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.ICLoader
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!o0CTJcdlL1U
IkarusPUA.FileTour
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]

How to remove UDS:Packed.Win32.Katusha?

UDS:Packed.Win32.Katusha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment