Malware

About “Win32/Packed.Obsidium.AS” infection

Malware Removal

The Win32/Packed.Obsidium.AS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Obsidium.AS virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Win32/Packed.Obsidium.AS?


File Info:

crc32: CA6884D4
md5: ccae0df5caad3b22357e4e60799fa8a0
name: f8ce1301c5a19f44.exe
sha1: 92f1ae1a956f6a7e7fbc297d71eeb8438133bf6b
sha256: 3bddda23559042412e7d5e5058791900477afadbd18eb9ada1da3e567fad7b1e
sha512: a8e6d76c217595a5764fda32cefb98c9dc869332464efc1e5f5ea339f28c6f5ebab7dffae562bc445d85859c2a667e6eaa689a0feae592a1782ad6ac01daaf40
ssdeep: 12288:C7WYXH+K9EjKBSlacebxfYlM8n4gUVgxW5+7LO:C7WYeKVWacmxfeM8n4gUKsoO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Packed.Obsidium.AS also known as:

MicroWorld-eScanTrojan.GenericKD.33035334
FireEyeGeneric.mg.ccae0df5caad3b22
CAT-QuickHealTrojan.Shellcode
Qihoo-360Win32/Trojan.Exploit.b27
McAfeeArtemis!CCAE0DF5CAAD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Shellcode.3!c
SangforMalware
K7AntiVirusTrojan ( 0052402c1 )
BitDefenderTrojan.GenericKD.33035334
K7GWTrojan ( 0052402c1 )
Cybereasonmalicious.5caad3
TrendMicroTROJ_GEN.R069C0PB320
BitDefenderThetaGen:NN.ZexaF.34090.Cq3@aOd0nfn
APEXMalicious
GDataTrojan.GenericKD.33035334
KasperskyExploit.Win32.Shellcode.nss
AlibabaExploit:Win32/Shellcode.616d1275
NANO-AntivirusTrojan.Win32.Razy.gymoxm
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.95 (RDML:ZHn0GkepVwQJqABtvnXMFQ)
Ad-AwareTrojan.GenericKD.33035334
SophosMal/EncPk-ANL
ComodoMalware@#3t15kz9pg97oo
F-SecureExploit.EXP/Shell.nvgea
Invinceaheuristic
McAfee-GW-EditionGeneric-FAWW!9BFB37CB90F9
EmsisoftTrojan.GenericKD.33035334 (B)
IkarusTrojan.Win32.Obsidium
CyrenW32/Trojan.NNTX-6298
JiangminExploit.ShellCode.va
AviraEXP/Shell.hidzg
Antiy-AVLTrojan[Exploit]/Win32.Shellcode
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F81446
ZoneAlarmExploit.Win32.Shellcode.nss
MicrosoftTrojan:Win32/Occamy.C
ALYacTrojan.GenericKD.33035334
MAXmalware (ai score=100)
VBA32BScope.TrojanSpy.Banker
ESET-NOD32a variant of Win32/Packed.Obsidium.AS
TrendMicro-HouseCallTROJ_GEN.R069C0PB320
TencentWin32.Exploit.Shellcode.Tbso
YandexExploit.Shellcode!kJcmaYDC3a8
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)
MaxSecureTrojan.Malware.74814073.susgen

How to remove Win32/Packed.Obsidium.AS?

Win32/Packed.Obsidium.AS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment