Malware

Win32/Packed.VMProtect.AU suspicious removal instruction

Malware Removal

The Win32/Packed.VMProtect.AU suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.VMProtect.AU suspicious virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Packed.VMProtect.AU suspicious?


File Info:

name: BFC293A5D5E740B9CEEC.mlw
path: /opt/CAPEv2/storage/binaries/7feb55bc8ffa6336fb77e8fc7a6f12a1f4369df092817c936e1affc6b0d2b243
crc32: 9ACADDFE
md5: bfc293a5d5e740b9ceece8d96d669166
sha1: 465c356c47eb8517a2460cb4151dcc081c15060f
sha256: 7feb55bc8ffa6336fb77e8fc7a6f12a1f4369df092817c936e1affc6b0d2b243
sha512: 5e194080667c8aeb765a799c4a03d57f3c9a55b69da01a551a2a5fdd508552caa75c0ccf3ec116174ef9dd40df05b020b874698b37351894f91b48ea0863da61
ssdeep: 196608:nUEvOROqC3AvqsuNkXXGtkfo4Yjo5nzY:UL1iAvq6jglWn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17886336721A511CAD0E4CD3A8A37FDA072F617AB4A83BC7D94ADADC524120B1B3D3D53
sha3_384: 3c5e28dc766ac3a0aab3e2b18cae33305370378043e56e4f7e8094f65e3d95b255b85131525dfeab8b137a80b61e55f1
ep_bytes: 56be842386039c66f7c6f46fe8d3509d
timestamp: 1971-07-24 12:38:40

Version Info:

FileDescription: DataExportTool.exe
FileVersion: 2.0.53.0
ProductVersion: 2.0.53.0
LegalCopyright: 版权所有 2006-2022 国家信息安全工程技术研究中心 保留所有权利
OriginalFilename: DataExportTool.exe
ProductName: 数据库助手
InternalName: DataExportTool.exe
Translation: 0x0804 0x04b0

Win32/Packed.VMProtect.AU suspicious also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGWin32:Malware-gen
MicroWorld-eScanTrojan.GenericKD.66296193
FireEyeGeneric.mg.bfc293a5d5e740b9
McAfeeArtemis!BFC293A5D5E7
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.176596
SangforTrojan.Win32.Packed.V5oq
K7AntiVirusTrojan ( 0059f3ce1 )
AlibabaPacked:Win32/VMProtect.f74eb690
K7GWTrojan ( 0059f3ce1 )
BitDefenderThetaGen:NN.ZexaF.36196.@Z0@aCeMM3hi
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.AU suspicious
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.66296193
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.66296193 (B)
VIPRETrojan.GenericKD.66296193
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.66296193
WebrootW32.Trojan.GenKD
MAXmalware (ai score=89)
Antiy-AVLTrojan[Packed]/Win32.VMProtect
ArcabitTrojan.Generic.D3F39981
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.GenericKD.66296193
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002H09D823
RisingTrojan.Generic@AI.87 (RDMK:cmRtazpCwUiLSnFj2k9p/yKZXO25)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
DeepInstinctMALICIOUS

How to remove Win32/Packed.VMProtect.AU suspicious?

Win32/Packed.VMProtect.AU suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment