Malware

Win32/Packed.Themida.DKA removal guide

Malware Removal

The Win32/Packed.Themida.DKA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.DKA virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

z.whorecord.xyz
a.tomx.xyz
crt.comodoca.com

How to determine Win32/Packed.Themida.DKA?


File Info:

crc32: 682EFBBE
md5: 416b6b6d2c9df4d8a3323c35099ca1f3
name: readit800-6395-setup.exe
sha1: ad048cce9b300b78ca2eb290652a60afd51535f0
sha256: d4978c396a9f9ef3c3e8b7afeeb671a5e50de045e6310a4309dff1dca8b49ddf
sha512: d0252b3344fe1663ee94cd800c7b4cf1b47ece332c72f75f4525276d52bdcb82af157b764adcf7581af51214d8f4b4cc38cd61871685265d048eb2476eb3a05d
ssdeep: 196608:e1Ocs2vDvjApGovlaYg/XjxADA7ZJd75Bt9pok64CI:AOCbjAAo8tNAwfHpl9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 xa9 1999-2010 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7z x5b89x88c5x81eax91cax653e
OriginalFilename: 7zS.sfx.exe
Translation: 0x0804 0x04b0

Win32/Packed.Themida.DKA also known as:

McAfeeArtemis!416B6B6D2C9D
K7AntiVirusTrojan ( 0055aafe1 )
K7GWTrojan ( 0055aafe1 )
AvastWin32:Trojan-gen
GDataWin32.Trojan.Agent.V9458O
KasperskyTrojan.MSIL.Phpw.gha
AlibabaTrojan:MSIL/Themida.71157b5f
SophosMal/Generic-S
ComodoMalware@#2pd9xv3t5tgnb
F-SecureTrojan.TR/Agent.yhwad
McAfee-GW-EditionArtemis
IkarusTrojan.Win32.Themida
AviraTR/Agent.yhwad
Antiy-AVLTrojan/MSIL.Phpw
MicrosoftProgram:Win32/Uwasson.A!ml
ZoneAlarmTrojan.MSIL.Phpw.gha
ESET-NOD32a variant of Win32/Packed.Themida.DKA
TrendMicro-HouseCallTROJ_GEN.R007H0CB820
FortinetW32/Generic!tr
AVGWin32:Trojan-gen

How to remove Win32/Packed.Themida.DKA?

Win32/Packed.Themida.DKA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment