Malware

How to remove “Win32/Packed.VMProtect.HF”?

Malware Removal

The Win32/Packed.VMProtect.HF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.VMProtect.HF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Deletes executed files from disk

How to determine Win32/Packed.VMProtect.HF?


File Info:

name: A5FB7EE697F8AE526F3C.mlw
path: /opt/CAPEv2/storage/binaries/c43fbe222d6bca8d686c24f4cdc562f31e4952d3c5d77aacce7764abaf26cc16
crc32: 3C3F2002
md5: a5fb7ee697f8ae526f3cbca7516503ae
sha1: 0365cf7f2a825ab28e4205d49ad3847dcfb84842
sha256: c43fbe222d6bca8d686c24f4cdc562f31e4952d3c5d77aacce7764abaf26cc16
sha512: 44e155e1259cc0452ff7dcd6041369259a235b2db23e03e0525c07a43d93323ae1f4a78a8bd82fed8872635c9607ccfea867b746444877849bae9d72669d63be
ssdeep: 98304:YOVaJA5Zo0h3rz6V08/hlmXR/xzgXnmdTHW9xrWUrm5dV4d:YOEJIo0h7z6V08aXR5zynmp2TrWUrm5d
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12346237363B10245E2E5C83DC937BCB471FA076B8E41A4B865AE65C42F256E1E313E93
sha3_384: ff4079423d1282fc073049553ae5f32d458c2fd8731d51c69212b9e9ac749d9768ac40c3393b7ca2fdd2f0dcd620429e
ep_bytes: 68c3f3b25ee858e71d00f9f7c10b7324
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Win32/Packed.VMProtect.HF also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
BitDefenderThetaGen:NN.ZexaF.34806.@FW@aSwdQ!c
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.HF
McAfee-GW-EditionBehavesLike.Win32.Sivis.tc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.a5fb7ee697f8ae52
SophosMal/VMProtBad-A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R363965
Acronissuspicious
VBA32BScope.Backdoor.DarkKomet
MalwarebytesMalware.AI.3057682417
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:ELED0H5tKuKPX/0rCfJd7g)
YandexTrojan.GenAsa!8lSyMKhnMjs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Packed.VMProtect.HF?

Win32/Packed.VMProtect.HF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment