Malware

Win64/Packed.VMProtect.DD removal instruction

Malware Removal

The Win64/Packed.VMProtect.DD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Packed.VMProtect.DD virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect

How to determine Win64/Packed.VMProtect.DD?


File Info:

crc32: 74972D4A
md5: 3c498a9d833c6267140a1e0071b13f78
name: 3C498A9D833C6267140A1E0071B13F78.mlw
sha1: 53c6ae6563d6e7bb51890721f57004ab55fd7ef7
sha256: dd000c2e0de82bad85640f039ae6fe40816d46e3654d8341bce421dad0831d6d
sha512: 37a88b7776a745854f5f5fdf1354434ca5d4ffecfe2231c2ce3379bbc8af10cb605375bd0a67eac0c0b0e6f8908108edc4539351b48ec30cc726408dde027288
ssdeep: 12288:XD1ju97kCgpdNyUSVNPI9p8dP/Yn6gkoYcTtv7IxVJb/ym8zqfVvRFAnfVlbGM:T1juWXN3kI9KC6giwmxVJb1PVZFAnt9
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

0: [No Data]

Win64/Packed.VMProtect.DD also known as:

K7AntiVirusTrojan ( 005262e21 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31155509
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaPacked:Win64/VMProtect.c0764ce5
K7GWTrojan ( 005262e21 )
Cybereasonmalicious.d833c6
CyrenW64/Agent.CGP.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.DD
APEXMalicious
AvastWin64:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.31155509
NANO-AntivirusTrojan.Win64.Mlw.fgluig
MicroWorld-eScanTrojan.GenericKD.31155509
TencentWin32.Trojan.Generic.Lkxt
Ad-AwareTrojan.GenericKD.31155509
SophosMal/Generic-S
ComodoMalware@#1sv8knixorsg5
McAfee-GW-EditionBehavesLike.Win64.Trickbot.bc
FireEyeGeneric.mg.3c498a9d833c6267
EmsisoftTrojan.GenericKD.31155509 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1100187
Antiy-AVLTrojan/Generic.ASMalwS.274740D
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.31155509
AhnLab-V3Unwanted/Win32.Agent.C2553286
Acronissuspicious
McAfeeGenericRXAA-FA!3C498A9D833C
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.VMP
PandaTrj/CI.A
YandexTrojan.GenAsa!9SUVGPLTYyU
IkarusTrojan.Win64.Vmprotect
FortinetW64/CoinMiner.AA!tr
AVGWin64:Malware-gen
Paloaltogeneric.ml

How to remove Win64/Packed.VMProtect.DD?

Win64/Packed.VMProtect.DD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment