Malware

Win64/Packed.VMProtect.H removal tips

Malware Removal

The Win64/Packed.VMProtect.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Packed.VMProtect.H virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect

How to determine Win64/Packed.VMProtect.H?


File Info:

crc32: E32C70C8
md5: c61823271a9c1c6aac36a0dc87f45437
name: C61823271A9C1C6AAC36A0DC87F45437.mlw
sha1: eba8a9e6b5bbf021d1c23eea84a1c4a03d65da00
sha256: 02f0bc1a65b62291c1ea56de7ea44f34b360e8fa40e031174048686e3a2fac0d
sha512: 46bf9ad905708f5bf412abdda313a78d1e6da4d62fac2e1bc4007d8098dea38fc4f6bab540b617c0153b331bfeed990d4da0bd2c360b50dbaa8286aefc2f60ac
ssdeep: 49152:j3Fh1jcXjEK2EpFkiuZzEVmjDRJMfwkRdo+P9aIQPG+PW7yNP2jN+W99QnrVj:pzsElEcim/e+S9B+ZW0n1
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win64/Packed.VMProtect.H also known as:

CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.6b5bbf
CyrenW64/S-ec191146!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.H
APEXMalicious
CynetMalicious (score: 99)
Kasperskynot-a-virus:HEUR:RiskTool.Win32.Generic
SophosGeneric PUA OL (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Generic.vc
FireEyeGeneric.mg.c61823271a9c1c6a
AviraHEUR/AGEN.1105696
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/CoinMiner.AC!bit
AhnLab-V3Unwanted/Win32.Agent.C2387031
McAfeeArtemis!C61823271A9C
VBA32Trojan.CoinMiner
MalwarebytesTrojan.MalPack.VMP
YandexTrojan.VMProtect!iDl0Fh3pxAY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Generic!tr
Paloaltogeneric.ml

How to remove Win64/Packed.VMProtect.H?

Win64/Packed.VMProtect.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment