Trojan

About “Trojan:Win32/VMProtect!MTB” infection

Malware Removal

The Trojan:Win32/VMProtect!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VMProtect!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.dlptcn.cn

How to determine Trojan:Win32/VMProtect!MTB?


File Info:

crc32: C2887D89
md5: db164c64e4d337ab30410dd2d16f252d
name: _________.exe
sha1: c8846c73bc2cd6dfefc967b89c9f46f4ae08c2fa
sha256: aa92ec9f5d909ca9b983f6e96b2af440d3030de39b1b87671bff92ad9045a007
sha512: d63b2bcaa321994be36c1931ccaf30918c96f49e6daa7120ddba736fef1f1bc129e938a7cd12ad0d146f6ac0a424d9d48b4933195e03d75aa490e68211e2f8e7
ssdeep: 98304:iqpaaIPpAU8d6vjsR6NjhYxiP8xX6hxJs/tFA:iqpRtd6vAR69XhxqH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: x5458x5de5x7aef.exe
FileVersion: 9.6.9.0
OriginalFilename: x5458x5de5x7aef.exe
ProductVersion: 9.6.9.0
Translation: 0x0804 0x03a8

Trojan:Win32/VMProtect!MTB also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Symmi.90304
FireEyeGeneric.mg.db164c64e4d337ab
McAfeePacked-GV!DB164C64E4D3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00563cb01 )
BitDefenderGen:Variant.Symmi.90304
K7GWTrojan ( 00563cb01 )
Cybereasonmalicious.4e4d33
TrendMicroTROJ_GEN.R002C0OEB20
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Vmprotect-6762068-1
GDataGen:Variant.Symmi.90304
KasperskyHEUR:Trojan.Win32.Generic
AlibabaPacked:Win32/VMProtect.14db399e
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareGen:Variant.Symmi.90304
EmsisoftGen:Variant.Symmi.90304 (B)
F-SecureTrojan.TR/Black.Gen2
DrWebTrojan.DownLoader33.40362
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.wc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.VMProtect
JiangminTrojan.Generic.eydai
AviraTR/Black.Gen2
MAXmalware (ai score=85)
Endgamemalicious (high confidence)
ArcabitTrojan.Symmi.D160C0
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/VMProtect!MTB
BitDefenderThetaGen:NN.ZexaF.34108.wF0@aOvOQ0hj
ALYacGen:Variant.Symmi.90304
VBA32Trojan.Wacatac
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.VMProtect.AB
TrendMicro-HouseCallTROJ_GEN.R002C0OEB20
RisingTrojan.Generic!8.C3 (CLOUD)
FortinetW32/Generic.GV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/VMProtect!MTB?

Trojan:Win32/VMProtect!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment