Malware

Win32/Packed.Themida.CDU removal guide

Malware Removal

The Win32/Packed.Themida.CDU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.CDU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: qytj.exe
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.46603.cn
a.tomx.xyz
aip.baidubce.com

How to determine Win32/Packed.Themida.CDU?


File Info:

crc32: 729A64E1
md5: 04305cfce02de1a92a5d6a4a82095886
name: qytj.exe
sha1: afe557f3381db646efc52bb306889a3d4946487d
sha256: 2213b409fce180c5e5c4bd8e1768056b56f37525683826d48d409926a323cb92
sha512: 42e7302274f3bc658395c5200ea498a1134da9b6f46d717aa7a47d3bece889704879059a35b0a6d39e5fc576968ccbbb0137be54eca9e86e161a24b840be326d
ssdeep: 98304:ZbQ2W1J7XL6sMgpSzPLlNwr9+BaXgwi1mSgHwnAQ6HCzShB7:VzQNL+YSzTvXH1qXLHCSv7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6d77x76d7 x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x6d77x76d7
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6d77x76d7x4f01x4e1ax4f01x70b9x6279x91cfx52a0x597dx53cb
ProductVersion: 1.0.0.0
FileDescription: x8054x7cfbQQ46603
Translation: 0x0804 0x04b0

Win32/Packed.Themida.CDU also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.32844905
FireEyeGeneric.mg.04305cfce02de1a9
CAT-QuickHealTrojandownloader.Phpw
McAfeeArtemis!04305CFCE02D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004eb1bf1 )
BitDefenderTrojan.GenericKD.32844905
K7GWTrojan ( 004eb1bf1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R023C0WLU19
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Application.PUPStudio.A
KasperskyTrojan-Downloader.Win32.Phpw.efi
AlibabaTrojanDownloader:Win32/Themida.95026d5a
NANO-AntivirusTrojan.Win32.Dwn.gwqjsg
AegisLabTrojan.Win32.Phpw.a!c
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan-downloader.Phpw.Cqy
Ad-AwareTrojan.GenericKD.32844905
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Agent.umvvh
DrWebTrojan.DownLoader32.42254
ZillyaTrojan.Themida.Win32.6786
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.rc
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.32844905 (B)
IkarusTrojan.Win32.Themida
CyrenW32/Trojan.ZXWB-5307
AviraTR/Dldr.Agent.umvvh
Antiy-AVLTrojan[Downloader]/Win32.Phpw
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F52C69
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
ZoneAlarmTrojan-Downloader.Win32.Phpw.efi
MicrosoftTrojan:Win32/Occamy.C
ALYacTrojan.GenericKD.32844905
MAXmalware (ai score=100)
VBA32Trojan.Antavmu
ESET-NOD32a variant of Win32/Packed.Themida.CDU
TrendMicro-HouseCallTROJ_GEN.R023C0WLU19
RisingTrojan.Generic@ML.97 (RDMK:Fa7fZb8xKghecI890dclzA)
YandexTrojan.DL.Phpw!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetRiskware/Generic
BitDefenderThetaGen:NN.ZexaF.34090.@B0aauxVQ!jb
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.3381db
PandaTrj/CI.A
Qihoo-360Script/Trojan.Downloader.f9d

How to remove Win32/Packed.Themida.CDU?

Win32/Packed.Themida.CDU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment