Malware

Win32/Packed.NoobyProtect.D suspicious removal guide

Malware Removal

The Win32/Packed.NoobyProtect.D suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.NoobyProtect.D suspicious virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
zzzzzz.me
cflt.qwq.ink
nodecache.zzzzzz.me
hm.baidu.com
ocsp.globalsign.com
ocsp2.globalsign.com
a.tomx.xyz
redirector.gvt1.com
r4—sn-4g5e6nzz.gvt1.com

How to determine Win32/Packed.NoobyProtect.D suspicious?


File Info:

crc32: 643FAFA5
md5: aa79f06d4c4dd05120bbdb7933d26caa
name: 93b81573826801.exe
sha1: 6352e2933588524343a97a06787b023d20d2ddfe
sha256: 6f94f3bfed26386223a20644049ef7905624153cb6e700ca47cf6babcbc438dc
sha512: 35cf3c24cfaa57d14eb7d9920d0fd62d5c5a73985175c361ccf7efdbfc6a91f9f6f80744736c4e7abd975c9c73e8593fd406311424b0f4552e6f51d75f7c5e3b
ssdeep: 49152:OZrN+H7lwGLv0ctTko87HvgMTIvFabrCDBqULMCaILmrEp+8A:OZpE2GLTpBqHvygrCDBqrMLQE6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5cf0x54e5x535ax5ba2xff1ahttp://zzzzzz.me/
FileVersion: 2.7.19.1115
CompanyName: x5cf0x54e5x535ax5ba2
Comments: SSRx8fdex63a5x5de5x5177
ProductName: F_SSRx8fdex63a5x5de5x5177
ProductVersion: 2.7.19.1115
FileDescription: SSRx8fdex63a5x5de5x5177
Translation: 0x0804 0x04b0

Win32/Packed.NoobyProtect.D suspicious also known as:

BkavHW32.Packed.
FireEyeGeneric.mg.aa79f06d4c4dd051
Qihoo-360Win32/Trojan.3bf
McAfeePacked-LF!AA79F06D4C4D
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005239691 )
K7GWTrojan ( 005239691 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Noobyprotect-6622929-0
GDataWin32.Riskware.NoobyProtect.B
KasperskyHEUR:Packed.Win32.Blackv.gen
AlibabaPacked:Win32/NoobyProtect.00d9dcfc
NANO-AntivirusTrojan.Win32.Blackv.gjgviv
RisingTrojan.Wacatac!8.10C01 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
ZillyaTrojan.Blackv.Win32.8
McAfee-GW-EditionBehavesLike.Win32.MoonLight.vc
Trapminemalicious.moderate.ml.score
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.NCZD-1162
JiangminPacked.Blackv.hbr
Antiy-AVLTrojan[Packed]/Win32.Blackv
ZoneAlarmHEUR:Packed.Win32.Blackv.gen
MicrosoftTrojan:Win32/Occamy.AA
Acronissuspicious
VBA32BScope.Trojan.Downloader
ESET-NOD32a variant of Win32/Packed.NoobyProtect.D suspicious
TencentWin32.Packed.Blackv.Lnxx
IkarusPUA.NoobyProtect
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.FKM!tr
BitDefenderThetaGen:NN.ZexaF.34110.Nw1@aS@dEQcb
AVGWin32:Malware-gen
Cybereasonmalicious.335885
Paloaltogeneric.ml
MaxSecureTrojan.Malware.12205601.susgen

How to remove Win32/Packed.NoobyProtect.D suspicious?

Win32/Packed.NoobyProtect.D suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment