Malware

Win32/Packed.Themida.AHT (file analysis)

Malware Removal

The Win32/Packed.Themida.AHT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.AHT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Packed.Themida.AHT?


File Info:

crc32: 0786E85E
md5: cc195a7d39d6c20a43ed57339c2fbc96
name: dn.opy
sha1: 6b87d1e6421c82a666135d265f81a22624a857e5
sha256: 6af255072547430417e72e86f0c204da087894e8429944bc9aa41a36f3ff12d9
sha512: 9e2fd852b3fa889b528db858f6db4fd188262ba1b0aede65b5d9742f7fce05b390de15872f99d3b2783d36d303111f0ab40d9da4c63e3cf49c2f9992150d3e37
ssdeep: 24576:xKyuaDlfJFtWx3pfuG1SN+WzkRQZZDu2eVZVgrQnzs:xPDRFw22DgrQzs
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Win32/Packed.Themida.AHT also known as:

BkavW32.HfsAutoB.
DrWebTrojan.Siggen8.26984
MicroWorld-eScanTrojan.GenericKD.41288974
FireEyeGeneric.mg.cc195a7d39d6c20a
McAfeeArtemis!CC195A7D39D6
CylanceUnsafe
VIPREBackdoor.Win32.Ircbot.gen (v)
SangforMalware
K7AntiVirusTrojan ( 004fca621 )
BitDefenderTrojan.GenericKD.41288974
Cybereasonmalicious.d39d6c
BitDefenderThetaGen:NN.ZexaF.34082.1uW@a4rMUQfi
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.41288974
AlibabaPacked:Win32/Themida.3d244387
NANO-AntivirusTrojan.Win32.TPM.fqhjru
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
Ad-AwareTrojan.GenericKD.41288974
EmsisoftTrojan.GenericKD.41288974 (B)
ComodoMalware@#fteykkjmwq4f
F-SecureTrojan.TR/Crypt.TPM.Gen
ZillyaTrojan.Packed.Win32.158673
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.TPM.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D276050E
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Packed/Win32.Agent.C3263041
Acronissuspicious
ALYacTrojan.GenericKD.41288974
MAXmalware (ai score=96)
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Themida.AHT
TencentWin32.Trojan.Crypt.Syht
YandexTrojan.Themida!
IkarusTrojan.Win32.Themida
eGambitTrojan.Generic
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM19.1.31ED.Malware.Gen

How to remove Win32/Packed.Themida.AHT?

Win32/Packed.Themida.AHT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment