Malware

How to remove “Packed.Win32.Generic”?

Malware Removal

The Packed.Win32.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packed.Win32.Generic virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
installsilver.top

How to determine Packed.Win32.Generic?


File Info:

crc32: 128B9B35
md5: f4610e422e102cb95f53e15001a8b380
name: 004.exe
sha1: 7806f99f28a2639d517e2bf96cbb6bfcb2e41c6c
sha256: d4faad8101988ef059af5910e818c8ab5df5e8a02bc0958fdf437a3f0a286a50
sha512: f31d65a7ef6bd905908bee5714f26b08e4a3b597490ad4c7507d5522e84a054e7a438ffb872306e8918fc8699d3f51fa203f01fb147a1f71487e9a9c861d5b74
ssdeep: 49152:iLJ7OIMMa3RpFdjhgFaJ5IapFS2jhaXtew21I5GphD+iovktJAIwoC:4w3pFdjvJ5VFSEhaXtecY+0vAIwoC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: CopyRight (C) 2019
InternalName: ByteDownload
FileVersion: 1, 0, 0, 2
CompanyName: 003
ProductName: ByteDownload Application
ProductVersion: 1, 0, 0, 2
FileDescription: ByteDownload Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: 003.EXE
Translation: 0x0804 0x04b0

Packed.Win32.Generic also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Midie.70743
FireEyeGeneric.mg.f4610e422e102cb9
Qihoo-360Win32/Trojan.3bf
McAfeePacked-LF!F4610E422E10
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Generic.x!c
SangforMalware
K7AntiVirusTrojan ( 005239691 )
BitDefenderGen:Variant.Midie.70743
K7GWTrojan ( 005239691 )
Cybereasonmalicious.f28a26
TrendMicroTROJ_GEN.R015C0PBQ20
BitDefenderThetaGen:NN.ZexaF.34096.Mw1@a0kZyvej
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Noobyprotect-6622929-0
GDataWin32.Riskware.NoobyProtect.B
KasperskyHEUR:Packed.Win32.Generic
AlibabaPacked:Win32/NoobyProtect.9054fa47
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Hookmoot!8.15EC (CLOUD)
Ad-AwareGen:Variant.Midie.70743
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1010504
ZillyaTrojan.Generic.Win32.1030925
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Injector.vc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Midie.70743 (B)
IkarusPUA.NoobyProtect
CyrenW32/Trojan.FMVD-1647
AviraHEUR/AGEN.1010504
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Midie.D11457
ZoneAlarmHEUR:Packed.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
ALYacGen:Variant.Midie.70743
MAXmalware (ai score=84)
MalwarebytesTrojan.Injector
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.NoobyProtect.G suspicious
TrendMicro-HouseCallTROJ_GEN.R015C0PBQ20
YandexRiskware.NoobyProtect!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetRiskware/Generic
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Packed.Win32.Generic?

Packed.Win32.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment