Malware

Win32/Packed.Themida.EGB removal

Malware Removal

The Win32/Packed.Themida.EGB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.EGB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: B8AA0EC2648094080BCDF8D61F328F5E.mlw
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
wwww.baidu.com
www.baidu.com
ss.bdimg.com
hectorstatic.baidu.com

How to determine Win32/Packed.Themida.EGB?


File Info:

crc32: 4367038F
md5: b8aa0ec2648094080bcdf8d61f328f5e
name: B8AA0EC2648094080BCDF8D61F328F5E.mlw
sha1: b185231852cdaf9cb51d8faa55780fdbbc3ca62e
sha256: 59ec43b591ce5830748efc8b82db2b9ffd490da831541bddfb144cf8de4d5fb6
sha512: 8e5c26c3314444063c9bb37c2793bb672bf1c98d999d0328432f716e68524b2d4c41278893621556c26653b8cb86046fa5d50d55b853259c30901508829ab98f
ssdeep: 24576:C7eTi3U/0etU79RSUUS8LkAFOqO/GqSa7C/91:CqTiyNykS8LfFUGe7O1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Packed.Themida.EGB also known as:

FireEyeGeneric.mg.b8aa0ec264809408
CAT-QuickHealWorm.VBNA
McAfeeArtemis!B8AA0EC26480
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/VBNA.b075eee2
K7GWTrojan ( 004eb1bf1 )
K7AntiVirusTrojan ( 004eb1bf1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.EGB
APEXMalicious
Paloaltogeneric.ml
KasperskyWorm.Win32.VBNA.bxnp
NANO-AntivirusTrojan.Win32.VB.fqfxge
AvastWin32:Malware-gen
RisingTrojan.Generic@ML.97 (RDMK:dmBMoDvLsZdR0B4rYCYOww)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.COC@52vn2u
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
Trapminemalicious.moderate.ml.score
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
AegisLabWorm.Win32.VBNA.o!c
ZoneAlarmWorm.Win32.VBNA.bxnp
AhnLab-V3Malware/Win32.Generic.C3218831
VBA32TScope.Malware-Cryptor.SB
MAXmalware (ai score=99)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CIC19
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.74181753.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.852cda
PandaTrj/Genetic.gen

How to remove Win32/Packed.Themida.EGB?

Win32/Packed.Themida.EGB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment