Malware

About “Win32:Pakes-D [Trj]” infection

Malware Removal

The Win32:Pakes-D [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Pakes-D [Trj] virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32:Pakes-D [Trj]?


File Info:

crc32: E4842CB9
md5: c90e7c88e6c7b7fac9b27e091599d5df
name: C90E7C88E6C7B7FAC9B27E091599D5DF.mlw
sha1: 256ac0171e5cbf4f711d56db9f510ca49dd2fe56
sha256: 0557545453650104b207793219aab52dcacde55ce013124064879a86c05cb1d6
sha512: b4254e41f1fad4dac0b70c1d12c0e375ac6d6302906f2831591cf98e70f312913bdb3c590e94fcbf9a57721b740c9f7d2faaf69b2fcae0f0635b7a4ca6f24ec8
ssdeep: 192:36k4HZ8fWDB2RWdoy2x446o/NFzNQljRqkKTuT00OGIjiHKhlH:3+OfWF2RWdoyO4ujVr4Y8
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

Translation: 0x0409 0x04e4
LegalCopyright: Copyright xa9 Microsoft Corp. 1988-1998
InternalName: CLICONFGx01
FileVersion: 1999.10.20
CompanyName: Microsoft Corporation
LegalTrademarks: Microsoftxae is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation
Comments: Windows
ProductName: Microsoft SQL Server
Platform: Windows
ProductVersion: 7.00.819
FileDescription: SQL Client Configuration Utilityx01
OriginalFilename: CLICONFG.EXEx01

Win32:Pakes-D [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed.20771
MicroWorld-eScanGen:Trojan.Heur.am1@ta!!Vpbi
ALYacGen:Trojan.Heur.am1@ta!!Vpbi
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.8e6c7b
CyrenW32/SuspPack.DH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Pakes-D [Trj]
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.am1@ta!!Vpbi
Ad-AwareGen:Trojan.Heur.am1@ta!!Vpbi
SophosML/PE-A + Mal/Packer
BitDefenderThetaAI:Packer.92F4B5A223
McAfee-GW-EditionBehavesLike.Win32.Backdoor.lc
FireEyeGeneric.mg.c90e7c88e6c7b7fa
EmsisoftGen:Trojan.Heur.am1@ta!!Vpbi (B)
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Trojan.Heur.am1@ta!!Vpbi
MAXmalware (ai score=80)
PandaMalicious Packer
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazqeyaXFmGo0vyD/RqBY4/Z/)
SentinelOneStatic AI – Malicious PE
AVGWin32:Pakes-D [Trj]

How to remove Win32:Pakes-D [Trj]?

Win32:Pakes-D [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment