Malware

What is “Win32/Packed.ORiEN.B suspicious”?

Malware Removal

The Win32/Packed.ORiEN.B suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.ORiEN.B suspicious virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Packed.ORiEN.B suspicious?


File Info:

crc32: 8469F536
md5: 7717fdfa037a54f574f5a693ed2f7bbf
name: 7717FDFA037A54F574F5A693ED2F7BBF.mlw
sha1: b7bd36dc8949a8f10b9b5a685acf51f4a4c6824d
sha256: fb8b27ec774cdcbcb275a2f8ee86dd1f2eb71f8ad8f7384e64b1d3de726e9917
sha512: dafbfa1c8497d64ae305104e7b1e977bca081117fee895cda4cd2eb05d9e46ddd5dd4b492c3fb93ff923d63f4bcc9c2bd975b6330f840eb76a97645bbb581129
ssdeep: 24576:+psY+YXdBNPqhTnezsTvo/WUJuYZLxTlbedKusK:+eYNXdyh9c/RuSRSdKu3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright? 2008-2009 IniCom Networks, Inc. All rights reserved.
InternalName: 4.x
FileVersion: 2009
CompanyName: www.mybr.org
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft(R) Windows(R) Operating System
SpecialBuild:
ProductVersion: 4.x
FileDescription: x5c0fx718ax8fdcx63a72009
OriginalFilename:
Translation: 0x0804 0x04b0

Win32/Packed.ORiEN.B suspicious also known as:

K7AntiVirusTrojan ( 7000000f1 )
MicroWorld-eScanGen:Trojan.Heur.kr0@rm!Rducj
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaPacked:Win32/ORiEN.a410ee1f
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.a037a5
CyrenW32/Heuristic-162!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.ORiEN.B suspicious
APEXMalicious
GDataGen:Trojan.Heur.kr0@rm!Rducj
BitDefenderGen:Trojan.Heur.kr0@rm!Rducj
Ad-AwareGen:Trojan.Heur.kr0@rm!Rducj
SophosMal/Packer
ComodoMalware@#1eomulz2nqurb
BitDefenderThetaAI:Packer.2D1832CA1C
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
Trapminemalicious.high.ml.score
FireEyeGen:Trojan.Heur.kr0@rm!Rducj
EmsisoftGen:Trojan.Heur.kr0@rm!Rducj (B)
SentinelOneDFI – Suspicious PE
F-ProtW32/Heuristic-162!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Malware.Gen
eGambitGeneric.Trojan
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Wacatac.C!ml
JiangminTrojan/Banload.a
ArcabitTrojan.Heur.E8E062
AegisLabTrojan.Win32.Whimoo.lrMp
Acronissuspicious
McAfeeArtemis!7717FDFA037A
MAXmalware (ai score=95)
TrendMicro-HouseCallTROJ_GEN.R002H0CBI20
RisingPUF.Packed-ORiEN!1.AA75 (CLOUD)
YandexRiskware.ORiEN!
IkarusTrojan-Downloader.Win32.Banload
FortinetPossibleThreat
AVGFileRepMetagen [Spy]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Spy.f2c

How to remove Win32/Packed.ORiEN.B suspicious?

Win32/Packed.ORiEN.B suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment