Threat Description

Packed: ?W32/PeCan.A


Category: Malware
Type: Packed
Platform: W32
Aliases: Packed:?W32/PeCan.A


This program is packed using a packer program associated with numerous other malware.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.

Suspect A False Alarm?

If you suspect a file has been incorrectly identified as malicious, (that is, it is a False Alarm or a False Positive), please first ensure your F-Secure security program is up-to-date with the latest detection database updates, then rescan the suspect file.

If you continue to suspect a False Alarm, you may submit a sample of the suspect file to our Security Labs for further analysis via the Sample Analysis System (SAS).

Technical Details

This program has been packed by the PeCancer packer program (hence the name of the detection).

Samples identified by the same detection perform one or more of the following activities:

  • Drop suspicious files or a copy of itself onto the system.
  • Set launch points to itself, or to the files it drops.
  • Some samples attempt to connect to and download from suspicious/malicious websites, for example:
    • hxxp://downxml.[..].cn/iepop/list/[..]
    • hxxp://downxml.[..].cn/iepop/update/[..]
    • hxxp://[..]
    • hxxp://[..]


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

F-Secure Community

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More