Malware

Should I remove “Win32/Packed.NoobyProtect_AGen.H suspicious”?

Malware Removal

The Win32/Packed.NoobyProtect_AGen.H suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.NoobyProtect_AGen.H suspicious virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Packed.NoobyProtect_AGen.H suspicious?


File Info:

name: 453E7E00C1E4A3F8D121.mlw
path: /opt/CAPEv2/storage/binaries/f140fd7ca0adf03ce594a768638866a845dbdb6edd721742604668e50de4a8d9
crc32: F14A3CEE
md5: 453e7e00c1e4a3f8d1212151b3a9e8e9
sha1: 973072f7a500e582e16aa24d7a9fd4ffb7a8a7b9
sha256: f140fd7ca0adf03ce594a768638866a845dbdb6edd721742604668e50de4a8d9
sha512: 3f676ba78b8cfb6674fbfa87328ed293dc9ee0eb50c0865b66da5be00c1be44d9ec194755b81ff7ffd9fd9722fd6b74a12a3d259acc6a1d56787e2843b7873e9
ssdeep: 24576:6JHr7Q1/xWKOQ+IoT2mycFehEsrEsWVs2p2FxDRjpXYYoNYFZRFLl82ddwkWwn:0A/oPLqAe5RjpoXYFZzLlU94
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AA5F1C1E5685333E1569CB0186B51CCEE2A0EF2143DF4BA13E35A4729712F9B73B49A
sha3_384: 9bd351870636be0811d1a2b3fb4a9259fd88831ac52922a10902e4694b24b8fba6372bcdbb8fb1f3601b3e144d93b31f
ep_bytes: e81c000000536166656e67696e652053
timestamp: 2013-04-07 09:33:59

Version Info:

FileVersion: 1.0.0.0
FileDescription: Auto UpdaterJinlanSoft
ProductName: JinlanSoft
ProductVersion: 1.0.0.0
LegalCopyright: JinlanSoft
Comments: JinlanSoft
Translation: 0x0804 0x04b0

Win32/Packed.NoobyProtect_AGen.H suspicious also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
FireEyeGeneric.mg.453e7e00c1e4a3f8
SkyhighBehavesLike.Win32.Generic.vh
MalwarebytesHupigon.Backdoor.Bot.DDS
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 005239691 )
K7AntiVirusTrojan ( 005239691 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.NoobyProtect_AGen.H suspicious
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Malware-gen
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
Antiy-AVLGrayWare/Win32.SafeGuard.a
XcitiumMalCrypt.Indus!@1qrzi1
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataWin32.Trojan.PSE.9G00EJ
VaristW32/S-b52d8ad2!Eldorado
AhnLab-V3Trojan/Win32.CaptchaSteal.R110021
Cylanceunsafe
RisingMalware.Blackv!8.E14F (TFE:5:Vwvh0g5GjZI)
IkarusPacked.Win32.NoobyProtect
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.36792.jw0@aC6VDibb
AVGWin32:Malware-gen
Cybereasonmalicious.7a500e
DeepInstinctMALICIOUS

How to remove Win32/Packed.NoobyProtect_AGen.H suspicious?

Win32/Packed.NoobyProtect_AGen.H suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment