Malware

Win32/Packed.Themida.FLM removal guide

Malware Removal

The Win32/Packed.Themida.FLM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.FLM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 3.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

vitya01.xyz

How to determine Win32/Packed.Themida.FLM?


File Info:

crc32: 349E9CFD
md5: c6545d383f0872752b428abbf68dc17f
name: 3.exe
sha1: 2d30d3289ee039580bd70031f1840834f45863b7
sha256: 9af532beae831fe7e3023994a804cd8135e3ec8df6a876d81e59bc115f1a062e
sha512: 2c1ba85706d0f14095fa1ec72bd7f50ddfb96bb85b7db00e9313db5c01e2cd1839273c76699bf07aebd277dd2d6111d72d6015a9f3f5da72187bdefa0c37cf0a
ssdeep: 49152:dPjLL/iBDRpNEhGMrlctLu6IbX9SnsfUe:dnriB7NEhGglka8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Packed.Themida.FLM also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanGenPack:Trojan.PWS.Delf.INS
McAfeeArtemis!C6545D383F08
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0040f4ef1 )
BitDefenderGenPack:Trojan.PWS.Delf.INS
K7GWTrojan ( 0040f4ef1 )
Cybereasonmalicious.83f087
ArcabitGenPack:Trojan.PWS.Delf.INS
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34090.OzWaai8Ayhk
ESET-NOD32a variant of Win32/Packed.Themida.FLM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaPacked:Win32/Themida.4dc797f6
AvastWin32:Trojan-gen
RisingStealer.Azorult!8.11176 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.Packed (A)
F-SecureTrojan.TR/Crypt.TPM.Gen
VIPREBackdoor.Win32.Ircbot.gen (v)
TrendMicroTROJ_FRS.0NA103BH20
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c6545d383f087275
SophosMal/Generic-S
IkarusTrojan.Win32.Themida
eGambitUnsafe.AI_Score_98%
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan.Win32.Generic
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGenPack:Trojan.PWS.Delf.INS
Ad-AwareGenPack:Trojan.PWS.Delf.INS
TrendMicro-HouseCallTROJ_FRS.0NA103BH20
TencentWin32.Trojan.Agent.Sxnw
SentinelOneDFI – Suspicious PE
GDataGenPack:Trojan.PWS.Delf.INS
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM19.1.5069.Malware.Gen

How to remove Win32/Packed.Themida.FLM?

Win32/Packed.Themida.FLM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment