Malware

What is “Win32/Obfuscated.NKV”?

Malware Removal

The Win32/Obfuscated.NKV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Obfuscated.NKV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Obfuscated.NKV?


File Info:

name: 0438A9CDACCC325AB0AC.mlw
path: /opt/CAPEv2/storage/binaries/d83155abd6f8140c2c53db83e0eb4126d6d03c65d99e649ec8de9d25b4e6c036
crc32: 96772257
md5: 0438a9cdaccc325ab0ac633b5f1e96da
sha1: d6eca7e2e7f0b88bda6e66ee77407484b4962024
sha256: d83155abd6f8140c2c53db83e0eb4126d6d03c65d99e649ec8de9d25b4e6c036
sha512: d8038eedd00cc1ba16f21342924fd56984ed4f7cae91107e867b58b8c27b9fd40c3499d87e453be7cef3c3ca1632698119d1a4ef198e674e00eb7b63741d5e76
ssdeep: 24576:ELK+idoEKbVe/tj7IjebqwQt8jQO/hEuqcC+HdSZhdLTv4Cc+ZCHdfd4tA8Sa:NYVGtjEjebbGpuqr+yTLTv1vIH9dL8Sa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1287501013B808035E7A507320669EAA6447DBD394BA596CFE3987E3D8E711D36B3371E
sha3_384: ed66fb485e1696e793b9e2381ec071da8d2808e5d4b41a432cd2cf2e1056a3df18b68b5c5b583d231dc1662e2765ed6d
ep_bytes: e84be70000e97ffeffffcccccccccccc
timestamp: 2016-10-19 09:40:14

Version Info:

CompanyName: UDa
FileDescription: UDa
FileVersion: 16.6.0.9
InternalName: SvrUpdat.exe
LegalCopyright: Copyright (C) 2016
OriginalFilename: SUpdat.exe
ProductName: UDa
ProductVersion: 16.6.0.9
Translation: 0x0804 0x04b0

Win32/Obfuscated.NKV also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebAdware.Mutabaha.1387
MicroWorld-eScanGen:Variant.Doina.8106
FireEyeGeneric.mg.0438a9cdaccc325a
CAT-QuickHealPUA.Beijingxin1.Gen
ALYacGen:Variant.Doina.8106
CylanceUnsafe
ZillyaTrojan.Obfuscated.Win32.77610
K7AntiVirusTrojan ( 004fbf691 )
AlibabaTrojan:Win32/Obfuscated.7b7ce26e
K7GWTrojan ( 004fbf691 )
Cybereasonmalicious.daccc3
VirITPUP.Win32.Beijing.L
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Obfuscated.NKV
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.8106
NANO-AntivirusRiskware.Win32.Mutabaha.ehpcpo
AvastWin32:Downloader-WGG [Trj]
TencentMalware.Win32.Gencirc.10b136bb
EmsisoftGen:Variant.Doina.8106 (B)
VIPREElex Installer (fs)
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
SophosTroj/SupTab-E
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.BrowseFox.foup
AviraPUA/Subtab.Gen7
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.1BF9260
MicrosoftTrojan:Win32/Occamy.C
SUPERAntiSpywarePUP.ELEX/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Doina.8106
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Adload.R190583
McAfeePUP-FKK
VBA32BScope.Adware.Mutabaha
MalwarebytesMalware.AI.2699689508
APEXMalicious
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!Lg59ey/WbnY
IkarusTrojan.Win32.Obfuscated
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AC.397F94!tr
AVGWin32:Downloader-WGG [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/Obfuscated.NKV?

Win32/Obfuscated.NKV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment