Malware

How to remove “Win32/Sohanad.NCB”?

Malware Removal

The Win32/Sohanad.NCB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Sohanad.NCB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Binary file triggered YARA rule
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable or modify Explorer Folder Options
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Sohanad.NCB?


File Info:

name: A81E2771EFE7DC180682.mlw
path: /opt/CAPEv2/storage/binaries/ee311cb984d0dfa810fb76516ff432291be08369064cfaffff47d8e066fa0739
crc32: 84156FB2
md5: a81e2771efe7dc18068251596ca6eb93
sha1: e14b5c904c6753a5dc9b832b119794c55b195da0
sha256: ee311cb984d0dfa810fb76516ff432291be08369064cfaffff47d8e066fa0739
sha512: 9deaa1ecb66f2c6b147975e631dee7838e9119224c56c8d154bb93efe8763223dac906c3e5f616f1b4b96cd3f37f00203c1bbd975384effa666c0543cc513b2f
ssdeep: 98304:GeVAJUgEq1UEJ1V14+Cnx/QG5paYnUGGt8GjtnvbIJBm4lxe25JxCCo+:GfUXq1bJ1V6RDHnUGojlvsteush+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15466220272D2F3F0D82958F50A5F63B453E56DFC6936AE0773D8BE2B64711A0E626213
sha3_384: 906744226c0a02b9664e3dc0262333cf4fb62534ec6bef2b63ef3202262dc7408f0df54c6c4e125b8b6ce71afe9d99cc
ep_bytes: e858b10000e917feffffb8bbfa4500a3
timestamp: 2004-05-24 01:48:42

Version Info:

FileDescription:
FileVersion: 3, 2, 10, 0
CompiledScript: AutoIt v3 Script : 3, 2, 10, 0
Translation: 0x0809 0x04b0

Win32/Sohanad.NCB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.Heur.AutoIT.2
FireEyeGeneric.mg.a81e2771efe7dc18
CAT-QuickHealWorm.Autoit.Sohanad.S
SkyhighBehavesLike.Win32.Sality.vc
McAfeeW32/Autorun.worm.f
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 000553661 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWEmailWorm ( 000553661 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.44866B6B18
SymantecW32.Imaut.BH
Elasticmalicious (high confidence)
ESET-NOD32Win32/Sohanad.NCB
APEXMalicious
TrendMicro-HouseCallWORM_SOHAND.SM
AvastWin32:Agent-AVDF [Trj]
ClamAVWin.Worm.Autoit-10020676-0
KasperskyIM-Worm.Win32.Sohanad.pw
BitDefenderGen:Trojan.Heur.AutoIT.2
NANO-AntivirusTrojan.Win32.Sohanad.tobaf
RisingMalware.FakeDOC/ICON!1.9C3B (CLASSIC)
EmsisoftGen:Trojan.Heur.AutoIT.2 (B)
BaiduWin32.Worm.Sohanad.az
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner2.18576
VIPREGen:Trojan.Heur.AutoIT.2
TrendMicroWORM_SOHAND.SM
Trapminemalicious.high.ml.score
SophosMal/Drpr-B
IkarusWorm.Win32.AutoRun
JiangminTrojan/Generic.bgqzb
Webrootnone
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/AutoIt.AY.gen!Eldorado
Antiy-AVLWorm/Win32.AutoRun.dtbv
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Sohanad.NCB@5geh8i
ArcabitTrojan.Heur.AutoIT.2
ViRobotWorm.Win32.IM-Sohanad.6511616
ZoneAlarmIM-Worm.Win32.Sohanad.pw
GDataGen:Trojan.Heur.AutoIT.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoit.2040320
VBA32Trojan-Downloader.Autoit.gen
ALYacGen:Trojan.Heur.AutoIT.2
Cylanceunsafe
PandaTrj/Autoit.gen
TencentWorm.Win32.AutoRun.f
YandexTrojan.Malagent.CUB
MAXmalware (ai score=100)
FortinetW32/Sohanad.A!worm
AVGWin32:Agent-AVDF [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm[im]:Win/Sohanad.NCB

How to remove Win32/Sohanad.NCB?

Win32/Sohanad.NCB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment