Malware

Win32/Packed.NoobyProtect.P suspicious information

Malware Removal

The Win32/Packed.NoobyProtect.P suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.NoobyProtect.P suspicious virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Packed.NoobyProtect.P suspicious?


File Info:

crc32: 75532B92
md5: 4de70a7cd24c11a9ba8d5a3884394fe4
name: bluem2_tx666.txt
sha1: 94a758213e790012e4e77901777d1f516f5c91c3
sha256: 696f955770433ea324c4dea45f361d0355bb41abc936a85d2b1514496910622d
sha512: ff11c6a5404963e5591ff6c6e5cdcc03933759d2641dce7b995bedecc1188c3f82e70aa279b4e0bb3870ba71571b38a7eeb0e9e60c000450a3077dcea09f1002
ssdeep: 49152:PubkpgqsHQBnQ+U9lroapdwsL3LfLNCeu+rtDTpJYnLO9g3O+I4Zgi9ycv3HYdfn:Pubi+P+WUarwsrLfS2Y13ONi5qUAu4p
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 2.0.1.28
CompanyName: bluem2
LegalTrademarks:
LastCompiledTime: 2016/07/02 01:52:52
Comments:
ProductName:
ProductVersion: 180618
FileDescription: BLUEM2x5ba2x6237x7aef
OriginalFilename:
Translation: 0x0804 0x03a8

Win32/Packed.NoobyProtect.P suspicious also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Cerbu.69619
FireEyeGeneric.mg.4de70a7cd24c11a9
MalwarebytesTrojan.Crypt
K7AntiVirusTrojan ( 005239691 )
BitDefenderGen:Variant.Cerbu.69619
K7GWTrojan ( 005239691 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.Lw0@aevIFymb
CyrenW32/Troj_Obfusc.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Dragon_i
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Cerbu.69619
AlibabaPacked:Win32/NoobyProtect.06006d8d
AegisLabTrojan.Win32.Cerbu.4!c
Ad-AwareGen:Variant.Cerbu.69619
SophosMal/Generic-S
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
F-SecureHeuristic.HEUR/AGEN.1010493
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Cerbu.69619 (B)
F-ProtW32/Troj_Obfusc.P.gen!Eldorado
AviraHEUR/AGEN.1010493
MAXmalware (ai score=83)
Endgamemalicious (high confidence)
ArcabitTrojan.Cerbu.D10FF3
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!4DE70A7CD24C
VBA32BScope.Trojan.StartPage
CylanceUnsafe
ESET-NOD32a variant of Win32/Packed.NoobyProtect.P suspicious
TrendMicro-HouseCallTROJ_GEN.R002H09CL20
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqBKt2cR0n5yMy4PZfYZ6vY)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Application
Cybereasonmalicious.13e790

How to remove Win32/Packed.NoobyProtect.P suspicious?

Win32/Packed.NoobyProtect.P suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment