Malware

Win32/Packed.DRMSoft.D suspicious information

Malware Removal

The Win32/Packed.DRMSoft.D suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.DRMSoft.D suspicious virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Packed.DRMSoft.D suspicious?


File Info:

name: 5FF6143C472C8F7C19A3.mlw
path: /opt/CAPEv2/storage/binaries/cf6720d1ddcd52ab1dc959ef2e8add9015309cbfba3b5c82503b3b69c9795585
crc32: 7FFD65D5
md5: 5ff6143c472c8f7c19a383a9d8b19c94
sha1: 762e6c1e6da65805e73b991092c34ef75ac6ed6d
sha256: cf6720d1ddcd52ab1dc959ef2e8add9015309cbfba3b5c82503b3b69c9795585
sha512: 22ae6dea3d6c30f495024181991524d0ed7b5d2dcfe0b6efa73537a1da448138efc7654895af72fc8ba6b1fd516a07069fb090d310e5c4f6dfd6ce3c50c6530d
ssdeep: 196608:paF8FVrNBirWE4rfY+YlQ4tjkqvYsCk/E3JwhepQv5v+INLcjy:paF8DNBirWL34FSsRiShXcjy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA96E122F2924433D06316789D5B93B99839BF201F2869C37BE87E4C5F396D13936297
sha3_384: 9c908a909f2e569b6b4025d603e3f8cbe958b49451aadad7693a10ffe2287ff9e8d97b26fefb8b077af1680b691ade76
ep_bytes: 558bec83c4f0b8989e4a00e884c7f5ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Packed.DRMSoft.D suspicious also known as:

BkavW32.AIDetectMalware
SangforPUP.Win32.Packed.V74u
AlibabaPacked:Win32/DRMSoft.822194bc
ESET-NOD32a variant of Win32/Packed.DRMSoft.D suspicious
APEXMalicious
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosGeneric Reputation PUA (PUA)
GDataWin32.Trojan.Agent.6TEKAP
Antiy-AVLTrojan[Packed]/Win32.DRMSoft
MicrosoftPUA:Win32/Presenoker
Cylanceunsafe
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.e6da65
DeepInstinctMALICIOUS

How to remove Win32/Packed.DRMSoft.D suspicious?

Win32/Packed.DRMSoft.D suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment