Malware

Win64/Packed.VMProtect.LO information

Malware Removal

The Win64/Packed.VMProtect.LO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Packed.VMProtect.LO virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect

How to determine Win64/Packed.VMProtect.LO?


File Info:

crc32: E1A5AD0D
md5: 99f86cf700ff068ed4ca2d22d048c454
name: 99F86CF700FF068ED4CA2D22D048C454.mlw
sha1: 67d36aa210cabc861e41289daab6efd1ddd68298
sha256: 69273edbd99a25f03598491e54f80afbfe1d3b18bdc14cbbf013b087da0e796f
sha512: cc418790124c5f5564acd7da887b2e8ecf3a425020e76943e27159dcfff737fe5cff6d8a0230744ba0d39c48cbe15e2446d0e8e124e81fb66668f72eb025f9e1
ssdeep: 49152:fx0T7s0NPyVwFFUKx6F8ggWTRtuVbdBhTWYjV4SI2df8RfucC5kFNlqHvqZc99p:fK7t9ysUKEFXM5jX/R8R6kNtZweA
type: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win64/Packed.VMProtect.LO also known as:

FireEyeGeneric.mg.99f86cf700ff068e
McAfeeArtemis!99F86CF700FF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
Cybereasonmalicious.210cab
InvinceaMal/VMProtBad-A
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyTrojan.Win64.Shelma.gas
SophosMal/VMProtBad-A
DrWebBackDoor.Meterpreter.157
ZillyaTrojan.Shelma.Win64.3800
McAfee-GW-EditionBehavesLike.Win64.Trickbot.wc
IkarusTrojan.Win64.Vmprotect
GDataWin32.Trojan-Downloader.Injector.VHRUSM
Antiy-AVLTrojan/Win64.Generic
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmTrojan.Win64.Shelma.gas
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
ESET-NOD32a variant of Win64/Packed.VMProtect.LO
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGWin64:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win64/Packed.VMProtect.LO?

Win64/Packed.VMProtect.LO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment