Malware

How to remove “Win32/Packed.MultiPacked.O”?

Malware Removal

The Win32/Packed.MultiPacked.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.MultiPacked.O virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/Packed.MultiPacked.O?


File Info:

crc32: 84318FE4
md5: 8fc8adfce398f9f150089fcc43019e60
name: 8FC8ADFCE398F9F150089FCC43019E60.mlw
sha1: 32498443ca313d09904293da3275d919ac3cc639
sha256: 82f356381a456b9e1c8ff820957fd7fb07e8c7d92356d362a140581faad354f3
sha512: c4f79a0f27d8e1a669968e9482984472528af9fb56da3e72eb9a73b1b9c359c1d9d699bd623e927cd56e8b3b9ea243f7ec2ef8c730bc3097f12aabd349fa1c5c
ssdeep: 24576:evesZCVPkiFjpiad6Cg1B43dYXdfIDymlYw+M+w7PBF63pYz+5F5pzvjGu5WxUWz:eIkiFNiNCK4KIDym1+w7Pz63ptpp7eUM
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Developed by MuldeR
InternalName: UHARC_GUI
FileVersion: 4.0.0.2
CompanyName: Developed by MuldeR
LegalTrademarks: Oi!
Comments: WORLD TRADE I$ A DEATH MACHINE
ProductName: UHARC_GUI
ProductVersion: v4.00
FileDescription: [UHARCx56fex5f62x524dx7aef]x72d0x72f8x5c11x7237x6c49x5316x7248
OriginalFilename: UHARC_GUI.exe
Translation: 0x0804 0x03a8

Win32/Packed.MultiPacked.O also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e39b1 )
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!8FC8ADFCE398
CylanceUnsafe
ZillyaTrojan.MultiPacked.Win32.14
SangforTrojan.Win32.Save.a
AlibabaPacked:Win32/MultiPacked.3242aeef
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.3ca313
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.MultiPacked.O
APEXMalicious
AvastWin32:Dropper-gen [Drp]
ViRobotTrojan.Win32.Z.Multipacked.1447044
SophosMal/Generic-S
ComodoHeur.Packed.MultiPacked@1z141z3
BitDefenderThetaGen:NN.ZelphiCO.34722.y5NaaGzFTKbb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Autorun.tc
FireEyeGeneric.mg.8fc8adfce398f9f1
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.Malware
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Heur!.032121A1
VBA32BScope.Trojan.Packed
MAXmalware (ai score=96)
IkarusTrojan.Win32.MultiPacked
AVGWin32:Dropper-gen [Drp]

How to remove Win32/Packed.MultiPacked.O?

Win32/Packed.MultiPacked.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment