Malware

How to remove “Win32/Packed.VMProtect.ABB”?

Malware Removal

The Win32/Packed.VMProtect.ABB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.VMProtect.ABB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Packed.VMProtect.ABB?


File Info:

name: D22BDC2B9C85DFF0180E.mlw
path: /opt/CAPEv2/storage/binaries/442dfaecd93a8cec3fd9116a68ed108045b01e6b388456f5e0b86e82afde4ad0
crc32: B87B3D7F
md5: d22bdc2b9c85dff0180edcae945c2632
sha1: 82a9b373f515b47d99a03e09f60899c780ae50e6
sha256: 442dfaecd93a8cec3fd9116a68ed108045b01e6b388456f5e0b86e82afde4ad0
sha512: 161ba7c5cba21373521c0f54d7def537b40022bff9da8602be693254fee4b1fa3e01e758851a88bb2957247e80d4f53971b20f67909f6c7e34923fffc739a738
ssdeep: 393216:JsCxtR/wrDDIQn4SBH0ysBoOhsCxtR/wrDDIQn4SBH0ysBoOq:J3tR/WIQLUysD3tR/WIQLUysg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0F63327946EE372C18509BD8A1A7BF650AFD83390E071A5A2C17CD9B4B3781DDC9393
sha3_384: 268bc5258afee76637f9426ac085bd0b461eed422d205817ac726b71bfef0a9d33925b0fe539da3bd4fcc12ae9de451a
ep_bytes: eb08094b030000000000e94d068aff35
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Synaptics
FileDescription: Synaptics Pointing Device Driver
FileVersion: 1.0.0.4
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
Comments:
Translation: 0x041f 0x04e6

Win32/Packed.VMProtect.ABB also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Ursu.784850
ALYacGen:Variant.Ursu.784850
CylanceUnsafe
K7AntiVirusTrojan ( 000112511 )
BitDefenderGen:Variant.Ursu.784850
K7GWTrojan ( 000112511 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecPacked.Vmpbad!gen38
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ABB
APEXMalicious
ClamAVWin.Malware.Vmprotect-6824127-0
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Variant.Ursu.784850
SophosMal/VMProtBad-A
F-SecureTrojan.TR/Black.Gen2
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
FireEyeGeneric.mg.d22bdc2b9c85dff0
EmsisoftGen:Variant.Ursu.784850 (B)
IkarusTrojan.Win32.VMProtect
GDataGen:Variant.Ursu.784850
JiangminWin32/Synaptics.Gen
AviraTR/Black.Gen2
ArcabitTrojan.Ursu.DBF9D2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeePacked-GV!D22BDC2B9C85
MAXmalware (ai score=85)
VBA32BScope.Trojan.Tiggre
MalwarebytesLamer.Virus.FileInfector.DDS
RisingTrojan.Generic@AI.98 (RDMK:cmRtazpevgYG0oJB4mneoaMSyiuK)
YandexTrojan.GenAsa!7r8sXhwfzXc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMprotect.7535!tr
BitDefenderThetaGen:NN.ZexaF.34638.@R0@a4zQKCjG
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.b9c85d
AvastWin32:Evo-gen [Susp]

How to remove Win32/Packed.VMProtect.ABB?

Win32/Packed.VMProtect.ABB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment