Malware

Win32/Packed.ScrambleWrapper.M potentially unwanted removal instruction

Malware Removal

The Win32/Packed.ScrambleWrapper.M potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.ScrambleWrapper.M potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to identify installed analysis tools by registry key
  • Detects VMware through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/Packed.ScrambleWrapper.M potentially unwanted?


File Info:

name: FD663A52329BF1AB837C.mlw
path: /opt/CAPEv2/storage/binaries/97a82972f2819b903f71cb04092ed7844af0eb81fc2058a995a4625f386ec0dc
crc32: B6354ABD
md5: fd663a52329bf1ab837cdb8ca3b846a3
sha1: f87bd15dfdd478f18309c7d8f519e409490cd18a
sha256: 97a82972f2819b903f71cb04092ed7844af0eb81fc2058a995a4625f386ec0dc
sha512: 6faf6934e69776f23758cc3f9f5d50f1fb063af7de46938113b6a61184cdea15d09da2a1d0f56d51e33a1252c5445f34485d0c1a95bb2dce8d77bef570de44d5
ssdeep: 98304:YXBk6yJ3zh1KChSgW7TLnPOr5n3BKSbUAwJr/M7u4I5Tpz6+aVRklN9a8hbQ0nuo:4k5jWCY7PPZSb3wJriopz6YLa8h7Zl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A77633F889CBAD77F54127330916C9BF95784F298012CEA32EE019F25C9B9149F1D92B
sha3_384: ca1f94a0680b3130d79826f5f94c93b19287b617c1b956beb37867c70bfc9eab481ad6eff14001292464ff2574884afd
ep_bytes: 5589e557565381ecac010000ff1574c3
timestamp: 2012-12-04 13:55:02

Version Info:

CompanyName: Xxplhgczxurvb
FileDescription: Eszasngcs
FileVersion: 3.5.4.21
LegalCopyright: Nvghkpotagrh
ProductName: Euvwbpb
Translation: 0x0409 0x0000

Win32/Packed.ScrambleWrapper.M potentially unwanted also known as:

FireEyeGeneric.mg.fd663a52329bf1ab
McAfeeArtemis!A5EF76CAD824
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004eb1481 )
BitDefenderAdware.GenericKD.30912215
K7GWUnwanted-Program ( 004eb1481 )
CrowdStrikewin/grayware_confidence_100% (D)
Elasticmalicious (high confidence)
ESET-NOD32Win32/Packed.ScrambleWrapper.M potentially unwanted
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.Agent.ajly
NANO-AntivirusRiskware.Win32.Agent.czwqxw
RisingMalware.ScrambleWrapper!8.324 (CLOUD)
ComodoApplicUnwnt@#172xtu03m482h
DrWebTrojan.Crossrider.17073
ZillyaAdware.Agent.Win32.169358
EmsisoftAdware.GenericKD.30912215 (B)
SentinelOneStatic AI – Malicious PE
GDataAdware.GenericKD.30912215
JiangminAdware/Agent.fda
AviraHEUR/AGEN.1231590
SUPERAntiSpywarePUP.CrossRider/Variant
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.MulDrop.C257381
ALYacAdware.GenericKD.30912215
MAXmalware (ai score=84)
VBA32AdWare.Agent
MalwarebytesPUP.Optional.CrossRider
YandexPUA.Agent!QhSTWNxDTDQ
IkarusPUA.CrossRider
FortinetAdware/Agent
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]

How to remove Win32/Packed.ScrambleWrapper.M potentially unwanted?

Win32/Packed.ScrambleWrapper.M potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment