Malware

Win32/Packed.AHK.A suspicious removal

Malware Removal

The Win32/Packed.AHK.A suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.AHK.A suspicious virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity

Related domains:

z.whorecord.xyz
www.sharpbot.org
a.tomx.xyz

How to determine Win32/Packed.AHK.A suspicious?


File Info:

crc32: C8CBCD44
md5: ef1aa6aba4f3c7a2a4e45190ca17aacc
name: EF1AA6ABA4F3C7A2A4E45190CA17AACC.mlw
sha1: ec3fc797bf2cf15de3facfa83d6c10c25fa17586
sha256: a54012ee21782a4e5667ee54ea1deb7d9016b73af20c0398b237f8389786833c
sha512: 2f2c8468ba766653e208e7e308392d65f6813773ba7f1a58fe51718e7d219a8f06dabe6e6b17e7d34545542644b9b3b28f5d337af7f92c161483977401ad17d2
ssdeep: 24576:2aFUxHHQs1TIy50dEE1/j2Ze5n2HqhxxlUR4Rb92w0jKpFGVftyfXOcA0lepIM7:2bw+5iEE16cUeb92w0jKpFGVVUXx7pM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.30.03
ProductName:
ProductVersion: 1.1.30.03
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Win32/Packed.AHK.A suspicious also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b96101 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.RP.Cz0@be44Ugli
CylanceUnsafe
SangforTrojan.Win32.AGEN.1006083
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Tiggre.38b9857a
K7GWTrojan ( 004b96101 )
Cybereasonmalicious.ba4f3c
CyrenW32/S-750ab906!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AHK.A suspicious
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Scar.vho
BitDefenderGen:Trojan.Heur.RP.Cz0@be44Ugli
MicroWorld-eScanGen:Trojan.Heur.RP.Cz0@be44Ugli
TencentWin32.Trojan.Gen.Alio
Ad-AwareGen:Trojan.Heur.RP.Cz0@be44Ugli
SophosMal/Generic-S
BitDefenderThetaAI:Packer.8B4189AA1F
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.ef1aa6aba4f3c7a2
EmsisoftGen:Trojan.Heur.RP.Cz0@be44Ugli (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1134582
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2C80AED
MicrosoftTrojan:Win32/Occamy.CA5
GDataGen:Trojan.Heur.RP.Cz0@be44Ugli
McAfeeArtemis!EF1AA6ABA4F3
MAXmalware (ai score=83)
VBA32BScope.Trojan.Fuerboos
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.98 (RDMK:n0UeTFc488srz89ogfqhOA)
MaxSecureTrojan.Malware.74657287.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Packed.AHK.A suspicious?

Win32/Packed.AHK.A suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment