Malware

Win64/Packed.VMProtect.JM malicious file

Malware Removal

The Win64/Packed.VMProtect.JM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Packed.VMProtect.JM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Win64/Packed.VMProtect.JM?


File Info:

name: 4EFFBA4D9A67D3737315.mlw
path: /opt/CAPEv2/storage/binaries/22e6e996b634a87e4d9c30713819932896b95a1c480c41224d6bbb6517a771d2
crc32: BA243FB1
md5: 4effba4d9a67d3737315fdc53d340c6e
sha1: 6db2f8754b3e5f36a444db310b1466a670142f70
sha256: 22e6e996b634a87e4d9c30713819932896b95a1c480c41224d6bbb6517a771d2
sha512: e7ec126927b62c36dd2dd4d4c139109a6d93f6b8daa20b284556a45da07e9088ea54a427727af0e43265066455a3627207817934e32ce9bd93b301f5b9bb8a2a
ssdeep: 12288:xHk5FbusHiVNxc6LaF86Wh7ACQtCv8hI:W66iDy6LB6Ms5h
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1598412AA48C9E27FCD4959796EF316CC3B773DEE820AD41BC0845F5259076A40E0EA6C
sha3_384: c8ceb646c4abd87bdf5574cc07489be8aa435f960a3f1fd37e5196bfb78a89ff31471325d181fd3a377915b30bcd0fc6
ep_bytes: e95a68faffe9dd1affff488d0483e9a8
timestamp: 2017-10-23 13:01:12

Version Info:

0: [No Data]

Win64/Packed.VMProtect.JM also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.BtcMine.1713
MicroWorld-eScanTrojan.GenericKD.30386330
FireEyeGeneric.mg.4effba4d9a67d373
McAfeeArtemis!4EFFBA4D9A67
CylanceUnsafe
K7AntiVirusTrojan ( 005251fc1 )
K7GWTrojan ( 005251fc1 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Generic.D1CFA89A
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.JM
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.30386330
NANO-AntivirusTrojan.Win64.BtcMine.faewfg
AvastWin64:CoinminerX-gen [Trj]
TencentWin32.Trojan.Generic.Piup
Ad-AwareTrojan.GenericKD.30386330
EmsisoftTrojan.GenericKD.30386330 (B)
ComodoMalware@#11ere13qmib9s
McAfee-GW-EditionBehavesLike.Win64.Generic.fc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112031
MAXmalware (ai score=95)
Antiy-AVLTrojan/Generic.ASMalwS.24E1092
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.30386330
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win64.Miner.R220000
Acronissuspicious
ALYacTrojan.GenericKD.30386330
MalwarebytesRiskWare.BitCoinMiner
APEXMalicious
YandexTrojan.GenAsa!409yNGvb9/A
IkarusPUA.CoinMiner
FortinetW32/Generic!tr
AVGWin64:CoinminerX-gen [Trj]
Cybereasonmalicious.d9a67d
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Win64/Packed.VMProtect.JM?

Win64/Packed.VMProtect.JM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment