Malware

About “Win32/Packed.CAB.AH suspicious” infection

Malware Removal

The Win32/Packed.CAB.AH suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.CAB.AH suspicious virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Packed.CAB.AH suspicious?


File Info:

crc32: 5A8BF89A
md5: 383ebcffd99777dbc7a2d7b81f0216cd
name: 383EBCFFD99777DBC7A2D7B81F0216CD.mlw
sha1: cb9e265e0b6939b55ad900ba9b8148dd1d16ce9a
sha256: 38e778a805895b5afe983e4ccfd97da4eba522f189331170f9f41cd902c05891
sha512: 38b104c61a67053bc0e2de97080dc9402dcb61abbeabe289978ef18067936e78a9d386fc6466b9d71b4072fc82f9dfe87b1a87c53ba9ef17a61a405bff43919a
ssdeep: 24576:Qt0s/Yb/GvmZTw4NhIBuw88I/1orkus9oUwZwgj0kX2nhSTJ6HOD9U90U1m6+lJ:QtSZNWB788q1owrzFg4k2hSVtRnHHg/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Qlhbymahm Ayiusrjpaj. Vcn Kznsuo Tovdmtly.
InternalName: Gogzzrm
FileVersion: 4.2.2302.57620 (uotfbjr_xef.157869-2230)
CompanyName: Qlhbymahm Ayiusrjpaj
PrivateBuild: Mvugw 8, 5806
ProductName: Fguxaucu Qhqephlk
ProductVersion: 4.2.2302.57620
FileDescription: Ddo44 Vgmkttz Yeyxpizzrd
OriginalFilename: CPSSZUT.EXE .MZN
Translation: 0x0409 0x04b0

Win32/Packed.CAB.AH suspicious also known as:

LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.e0b693
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.CAB.AH suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!383EBCFFD997
MalwarebytesSpyware.PasswordStealer
FortinetW32/Malicious_Behavior.VEX
Paloaltogeneric.ml

How to remove Win32/Packed.CAB.AH suspicious?

Win32/Packed.CAB.AH suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment