Trojan

About “Trojan:Win32/VMProtect” infection

Malware Removal

The Trojan:Win32/VMProtect is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VMProtect virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Hungarian
  • The binary likely contains encrypted or compressed data.
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/VMProtect?


File Info:

crc32: 724BA220
md5: 861ce2ab9dc90d084445d0d0b228b36e
name: 861CE2AB9DC90D084445D0D0B228B36E.mlw
sha1: 3811d1dc4653002803e4ea2d25d0925f87136556
sha256: 6a59aefc3523954ea8fdeabfe40bf0a7ba290a98fa0c92abe7b3b0837ce2f927
sha512: 8dc707c76cef790a2c915fc2f7cc009114d9462ecc6eda533e53c4577aa77f1ff227ae0642750130be16e17da8ce8cce76bad54801fdfb5c9a23b9de4c0ba072
ssdeep: 49152:qI1NfS3Giwb5P7hSmS/mtK2le8RB1MLd0VzvRLI:XvSWEny9lend0B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/VMProtect also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000001c1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Dynamer
ALYacGen:Variant.Razy.495317
CylanceUnsafe
ZillyaTrojan.Packed.Win32.91555
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/VMProtect.0ccb8c81
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.b9dc90
BaiduWin32.Packed.VMProtect.a
SymantecPUA.Keygen
ESET-NOD32a variant of Win32/Packed.VMProtect.ABD
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-6188890-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.495317
NANO-AntivirusTrojan.Win32.Razy.ellmdr
SUPERAntiSpywareTrojan.Agent/Gen-Razy
MicroWorld-eScanGen:Variant.Razy.495317
Ad-AwareGen:Variant.Razy.495317
SophosMal/Generic-R + Mal/VMProtBad-A
ComodoMalware@#29fq1bgu8eeu4
F-SecureTrojan.TR/Black.Gen2
BitDefenderThetaGen:NN.ZexaF.34738.ITW@aKeHgPlG
VIPRETrojan.Win32.Generic!BT
TrendMicroCRCK_KEYGEN
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.861ce2ab9dc90d08
EmsisoftGen:Variant.Razy.495317 (B)
SentinelOneStatic AI – Suspicious PE
WebrootPUA.Gen
AviraTR/Black.Gen2
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.1C67BB6
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/VMProtect
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Razy.D78ED5
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Razy.495317
AhnLab-V3Unwanted/Win32.KeyGen.C1664961
McAfeeGenericRXAA-AA!861CE2AB9DC9
MAXmalware (ai score=96)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.2947177946
PandaTrj/CI.A
TrendMicro-HouseCallCRCK_KEYGEN
RisingTrojan.Generic@ML.100 (RDMK:l7Itw14i88eH08HZncJu2Q)
YandexTrojan.GenAsa!DKm3EUicv/M
Ikarusnot-a-virus.Keygen.xForce
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.7112!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/VMProtect?

Trojan:Win32/VMProtect removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment