Categories: Malware

Win32/Packed.GHFProtector.A suspicious (file analysis)

The Win32/Packed.GHFProtector.A suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.GHFProtector.A suspicious virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/Packed.GHFProtector.A suspicious?


File Info:

crc32: B5B26067md5: e886808d3e13c73d29db441f3b694208name: E886808D3E13C73D29DB441F3B694208.mlwsha1: 088588b0a642a1cef91e25307148bc9ed7780018sha256: de5bc658640e7a16b0be17234bc2cddef6fa96b0172d001642e90183bdcb9e65sha512: 1b45e5dd6b1bf1a6678e3ce382d7642651f8fff81174405616cbfadba204fde3456e49ffb9287f141b22ba34e00dd3b0652630f539721482ffa8241af8bcedc1ssdeep: 12288:L1PWDSo9px9Pw7x7glxjGIhtnyMQ2+lQGbyfLFjkAMdT:K9Jo9glxF7yMQ28QxLRkAMtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Packed.GHFProtector.A suspicious also known as:

Bkav W32.AIDetect.malware2
K7AntiVirus Trojan ( 0054e4141 )
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
ALYac Trojan.GenericKD.46061393
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Malware:Win32/km_28f0ee.None
K7GW Trojan ( 0054e4141 )
Cybereason malicious.0a642a
Cyren W32/Troj_Obfusc.Z.gen!Eldorado
Symantec Bloodhound.Morphine
ESET-NOD32 a variant of Win32/Packed.GHFProtector.A suspicious
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Trojan.Packed-85
Kaspersky VHO:Backdoor.Win32.Convagent.gen
BitDefender Trojan.GenericKD.46061393
MicroWorld-eScan Trojan.GenericKD.46061393
Tencent Win32.Adware.Generic.Alik
Ad-Aware Trojan.GenericKD.46061393
Sophos ML/PE-A + Mal/EncPk-ZE
Comodo TrojWare.Win32.PkdMorphine.~AN@1l4q0o
BitDefenderTheta AI:Packer.B04F28931F
VIPRE Packer.Morphine.Gen (v)
TrendMicro Cryp_Morphine
McAfee-GW-Edition BehavesLike.Win32.VirRansom.hc
FireEye Generic.mg.e886808d3e13c73d
Emsisoft Trojan.GenericKD.46061393 (B)
SentinelOne Static AI – Suspicious PE
Jiangmin Packed.Morphine.a
Avira TR/Crypt.Morphine.Gen
eGambit Unsafe.AI_Score_99%
Microsoft VirTool:Win32/Obfuscator.EK
Arcabit Trojan.Generic.D2BED751
AegisLab Trojan.Win32.Convagent.m!c
ZoneAlarm Packed.Multi.SuspiciousPacker.gen
GData Trojan.GenericKD.46061393
Acronis suspicious
McAfee Artemis!E886808D3E13
MAX malware (ai score=82)
Malwarebytes Malware.Heuristic.1001
Panda Trj/GdSda.A
TrendMicro-HouseCall Cryp_Morphine
Yandex Packed/Morphine
Ikarus Backdoor.Win32.Rbot
Fortinet Adware/Generic
AVG Win32:Malware-gen
Paloalto generic.ml
Qihoo-360 Win32/Trojan.Obfuscated.HxMBepsA

How to remove Win32/Packed.GHFProtector.A suspicious?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.2972915474 malicious file

The Malware.AI.2972915474 is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

Win32/Autoit.OPN information

The Win32/Autoit.OPN is considered dangerous by lots of security experts. When this infection is active,…

47 mins ago

Malware.AI.3788326785 removal

The Malware.AI.3788326785 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

What is “Trojan.Generic.35619263”?

The Trojan.Generic.35619263 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Generic.Dacic.1A7FA519.A.F34D6DE8 removal instruction

The Generic.Dacic.1A7FA519.A.F34D6DE8 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “Babar.143901”?

The Babar.143901 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago