Malware

About “Packed.Win32.Gena.b” infection

Malware Removal

The Packed.Win32.Gena.b is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packed.Win32.Gena.b virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Packed.Win32.Gena.b?


File Info:

name: F214FF78AABC2F55804B.mlw
path: /opt/CAPEv2/storage/binaries/87dc92e2e4b7bf80c74ba43cc9c31ae9cb0041763f96021b7d70180476fe5db4
crc32: D714B855
md5: f214ff78aabc2f55804b929c15267803
sha1: dd9c72cfa25a77b7e7353cf94bdb9bd94272be1a
sha256: 87dc92e2e4b7bf80c74ba43cc9c31ae9cb0041763f96021b7d70180476fe5db4
sha512: 0f1ff7ca2c16c94f9eb78987301992b0189d8b261ac60f879bdbdb047d70e1be6838a3cafb024eb881c890e90aacdcc1c1b9a8cee1b9866605db33c973115495
ssdeep: 1536:gxZ2cVl5mu5nouy8EY3qCZQX2oooD+AyxArXIVJ9K:gxZ2cViioutEYaIQXMmXIM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166639D43AB454B8BE479027058DBEA171936EC98CD94C77384D8BD730EA3B6A943F312
sha3_384: 6b9472c1be146cd58ea34c1d415b73b4540f39ca3d55a3e6899795749059309a73843ec2bace385241e01bea0985922f
ep_bytes: 60be004041008dbe00d0feff5789e58d
timestamp: 2014-06-05 06:43:59

Version Info:

Comments:
CompanyName:
FileDescription: Microsoft(R) Windows(R) Operating System
FileVersion: 6, 0, 2900, 5512
InternalName:
LegalCopyright: 版权所有 (C) 2013
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Microsoft
ProductVersion: 6.00.2900.5512
SpecialBuild:
Translation: 0x0804 0x04b0

Packed.Win32.Gena.b also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent2.m2HQ
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur.em0@!thi1Dkb
FireEyeGeneric.mg.f214ff78aabc2f55
ALYacGen:Trojan.Heur.em0@!thi1Dkb
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaPacked:Win32/Generic.96aaf0df
BaiduWin32.Trojan.Kryptik.gp
CyrenW32/Trojan-Gypikon-based.BA!Max
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyPacked.Win32.Gena.b
BitDefenderGen:Trojan.Heur.em0@!thi1Dkb
NANO-AntivirusTrojan.Win32.PolyCrypt.dpmiea
AvastWin32:Malware-gen
Ad-AwareGen:Trojan.Heur.em0@!thi1Dkb
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREGen:Trojan.Heur.em0@!thi1Dkb
TrendMicroTROJ_GEN.R002C0PG222
McAfee-GW-EditionGenericRXEY-BF!F214FF78AABC
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.em0@!thi1Dkb (B)
IkarusTrojan.Win32.Agent2
GDataGen:Trojan.Heur.em0@!thi1Dkb
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.1Table.R502303
McAfeeGenericRXEY-BF!F214FF78AABC
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002C0PG222
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ULPM.16C0!tr
BitDefenderThetaAI:Packer.31165CDF1C
AVGWin32:Malware-gen
Cybereasonmalicious.8aabc2

How to remove Packed.Win32.Gena.b?

Packed.Win32.Gena.b removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment