Malware

About “Win32/Packed.Autoit.NBB suspicious” infection

Malware Removal

The Win32/Packed.Autoit.NBB suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Autoit.NBB suspicious virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Win32/Packed.Autoit.NBB suspicious?


File Info:

crc32: 4C0139EE
md5: 713f52c5edd3db4f215c023da93721ae
name: 713F52C5EDD3DB4F215C023DA93721AE.mlw
sha1: 221188919f974f2602ce7d735670aa981cf81191
sha256: 490bea86f6adfb047a13ff2e31ccc40f8d679c1a58c58afc4b8b883011b040c1
sha512: 2d793b18d662c4c4860b10e538a9044bea78fb5762d98b3254477e0bf8325f40834cd17b1b5a4754e97a88bb2e7af3a30cc6ae4cb6e331e6485af6697a7452ff
ssdeep: 12288:FidnDiTpURF4fd8okh2J/pcYFteV5iKJoSy7Khyb2HYL:Fvs88okwJ/pF4TiXKQbXL
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Free
FileVersion: 2.0.6.6
Comments: Compiled 2019Q2
Productname: x5c40x57dfx7f51x5171x4eabx4e00x952ex901a
ProductVersion: 2.0.6.6
FileDescription: http://www.xyboot.com/
Translation: 0x0804 0x04b0

Win32/Packed.Autoit.NBB suspicious also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.32081565
FireEyeGeneric.mg.713f52c5edd3db4f
CAT-QuickHealTrojan.Tiggre
McAfeeArtemis!713F52C5EDD3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0054e86c1 )
BitDefenderTrojan.GenericKD.32081565
K7GWTrojan ( 0054e86c1 )
Cybereasonmalicious.5edd3d
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
AlibabaPacked:Win32/Generic.3c936e24
NANO-AntivirusTrojan.Win32.Stealer.fgibef
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareTrojan.GenericKD.32081565
SophosMal/Generic-S
ComodoMalware@#2d3bkvy48afdt
F-SecureTrojan.TR/Worm.Gen
TrendMicroTROJ_GEN.R005C0DHU20
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.32081565 (B)
IkarusTrojan.Worm
MaxSecureTrojan.Malware.7175203.susgen
AviraTR/Worm.Gen
Antiy-AVLGrayWare/Autoit.BinToStr.a
MicrosoftTrojan:Win32/Zenpack!ml
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Generic.D1E9869D
GDataTrojan.GenericKD.32081565
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.32081565
PandaTrj/CI.A
ESET-NOD32Win32/Packed.Autoit.NBB suspicious
TrendMicro-HouseCallTROJ_GEN.R005C0DHU20
TencentWin32.Trojan.Falsesign.Aeeh
FortinetRiskware/Application
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Generic.99b

How to remove Win32/Packed.Autoit.NBB suspicious?

Win32/Packed.Autoit.NBB suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment