Trojan

Trojan:Win32/Thetatic.A (file analysis)

Malware Removal

The Trojan:Win32/Thetatic.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Thetatic.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A scripting utility was executed
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Thetatic.A?


File Info:

crc32: 9885DE8A
md5: ec9ae4c3935b717769a5b3a3fa712943
name: afa8d185de2f357082ed4042fc057a6d7300f603d3bfdbe7e6c351868e45e477
sha1: f367cf38450be6b41f8d6687daf08725872f7587
sha256: afa8d185de2f357082ed4042fc057a6d7300f603d3bfdbe7e6c351868e45e477
sha512: 0e58535fb007f062377824c6d65ad6e7577db26841a689d66ba3f1c9f5c5448eb7f2ffbd5912545b4bec6233eb7fe434b52e285f5cb9bdda4031e39ee01b269b
ssdeep: 768:/SS1NQZz8P+PiB9wZ3lopxolh99XsN8A4nx:/SS1udn3hlhvXO8AQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Thetatic.A also known as:

MicroWorld-eScanGen:Variant.Unruy.1
ALYacGen:Variant.Unruy.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Unruy.1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3935b7
F-ProtW32/WMIGhost.B.gen!Eldorado
SymantecTrojan Horse
AVGWin32:Trojan-gen
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-883585
GDataGen:Variant.Unruy.1
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Thetatic.4cca24d7
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.A.Gupd.49452.A
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ag.Anfu
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Unruy.1 (B)
ComodoMalware@#2pf9yyfpw4ssp
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader26.55441
ZillyaTrojan.Syndicasec.Win32.1
TrendMicroTROJ_AGENT_031681.TOMB
McAfee-GW-EditionGeneric Trojan.he
FireEyeGeneric.mg.ec9ae4c3935b7177
SophosTroj/Thetatic-C
SentinelOneDFI – Suspicious PE
CyrenW32/WMIGhost.B.gen!Eldorado
JiangminTrojan/Generic.aaxjn
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Gupd
ArcabitTrojan.Unruy.1
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Thetatic.A
AhnLab-V3Win-Trojan/Thetatic.45056
McAfeeGeneric Trojan.he
MAXmalware (ai score=100)
Ad-AwareGen:Variant.Unruy.1
ESET-NOD32Win32/Syndicasec.G
TrendMicro-HouseCallTROJ_AGENT_031681.TOMB
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.Agent!KNNIrOXWuPg
IkarusTrojan.Win32.Thetatic
eGambitUnsafe.AI_Score_99%
FortinetW32/Syndicasec.F!tr
VBA32BScope.Trojan.Gupd
PandaGeneric Malware
Qihoo-360Win32/Trojan.207

How to remove Trojan:Win32/Thetatic.A?

Trojan:Win32/Thetatic.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment