Malware

About “Win64/Packed.VMProtect.IY” infection

Malware Removal

The Win64/Packed.VMProtect.IY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Packed.VMProtect.IY virus can do?

  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win64/Packed.VMProtect.IY?


File Info:

name: CC79DCDD4B4CC4842DA2.mlw
path: /opt/CAPEv2/storage/binaries/84607aaeda001a7cb4c2bab1d5be40f21f1a4ca83b2ab94c2819d00b4b20f63e
crc32: F72009BE
md5: cc79dcdd4b4cc4842da2926c1e77205b
sha1: c107af78e8679d2b41830066078bf212c63d293f
sha256: 84607aaeda001a7cb4c2bab1d5be40f21f1a4ca83b2ab94c2819d00b4b20f63e
sha512: 1931648ad58ea5874ebee2a900c2e433cd32146283e0f446f9dcf1b851f0034a904c20fcc264e94ef733298649ba5cf769ba6d52e4a9d907ee804f344e9caa0e
ssdeep: 49152:p9x4uKcwgOcbRBZE4A8Ivp2DucTZt+h2GUAH0QxN0sgny6GWxULSN6q4G/P8O2P1:p9e5C1frAf0DJ+oYUQxWsgxhNt4ScGw
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T13AF501ED6244336CC42DC5709037FD05F275166E13EAD5AAB2CB7BD07BAB460A902F4A
sha3_384: 8fc864a93a51f1fc2839a8368cc093bfd5b6602caa36df1802912aff9c59b6ada24e381181fc56fec2ce260f378262eb
ep_bytes: 68b83ea09ee8409f1200bedece5ded9e
timestamp: 2021-11-22 03:06:10

Version Info:

0: [No Data]

Win64/Packed.VMProtect.IY also known as:

DrWebTrojan.PWS.Stealer.29444
MicroWorld-eScanTrojan.GenericKD.47514605
FireEyeGeneric.mg.cc79dcdd4b4cc484
McAfeeArtemis!CC79DCDD4B4C
ZillyaTrojan.VMProtect.Win64.7892
K7AntiVirusTrojan ( 0055f1be1 )
AlibabaPacked:Win64/VMProtect.a79e3b65
K7GWTrojan ( 0055f1be1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.IY
BitDefenderTrojan.GenericKD.47514605
AvastWin64:DangerousSig [Trj]
Ad-AwareTrojan.GenericKD.47514605
EmsisoftTrojan.GenericKD.47514605 (B)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin64.Trojan.Agent.6O7RDJ
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
APEXMalicious
RisingTrojan.MalCert!1.CF96 (CLASSIC)
IkarusTrojan.Win64.Vmprotect
FortinetW32/PossibleThreat
AVGWin64:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win64/Packed.VMProtect.IY?

Win64/Packed.VMProtect.IY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment