Malware

Win32/Packed.VMProtect.NI (file analysis)

Malware Removal

The Win32/Packed.VMProtect.NI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.VMProtect.NI virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Packed.VMProtect.NI?


File Info:

name: D9738AD30143493D6EC1.mlw
path: /opt/CAPEv2/storage/binaries/069a1930605006692a1f0094c90f2bfc1ab137ff1fc9267793ae50d02da05bbd
crc32: EFCEAEC5
md5: d9738ad30143493d6ec1d47d7c05ee88
sha1: 712e8b8ebd8fbf5035dc5f88e28cab582a98c849
sha256: 069a1930605006692a1f0094c90f2bfc1ab137ff1fc9267793ae50d02da05bbd
sha512: 3b822479694353999c0d30dde9a607394de6a32c2d095c5b8ad8d6cfc1047a410f09f7e6b967b23684e978501c588197e440d4aae8d7c75b4e334f324c6b04e2
ssdeep: 98304:WckDd9iQBLy0SuZivwxcEwqxx4nHfvyw0vTKiZijBL42m7nRv6J:vInZZiopxxOHfv90vTKd1+zh6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15746237312652282E1F28D3D9537FDB472F70E5B5A42AC7864D6ADC33A568E4E303D82
sha3_384: c3da3b96774b2787486d3dcf5e50d56a98a67818f1d824477fc49e85f8c46dfd58c30f23c3d99f7f843116227ed89a30
ep_bytes: 68bda272cae83f380d006645896f089c
timestamp: 2011-07-03 09:05:04

Version Info:

0: [No Data]

Win32/Packed.VMProtect.NI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Malicious.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.d9738ad30143493d
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!D9738AD30143
Cylanceunsafe
ZillyaTrojan.VMProtect.Win32.9506
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058b79c1 )
K7GWTrojan ( 0058b79c1 )
Cybereasonmalicious.ebd8fb
BitDefenderThetaGen:NN.ZexaF.36680.@BW@aCClfMni
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.NI
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Trojan-gen
F-SecureTrojan.TR/Crypt.XPACK.Gen
SophosMal/Generic-S
IkarusTrojan.Win32.VMProtect
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R300174
VBA32BScope.Trojan.Vigorf
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Emelent!8.F6ED (TFE:5:BYqjbponmRK)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Packed.VMProtect.NI?

Win32/Packed.VMProtect.NI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment