Malware

Win32/Packed.Themida.Gen.DN (file analysis)

Malware Removal

The Win32/Packed.Themida.Gen.DN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.Gen.DN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: word.exe
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Win32/Packed.Themida.Gen.DN?


File Info:

crc32: 03B8320B
md5: b995a3cfedaf936ddd78a4152669d141
name: word.exe
sha1: 1e09b494ea7ac81d6d18a2af1148b04bdb81e387
sha256: 1be70b3d1d5bd55e8dfab4c3a3d77db1cb25127f7283b6a106c379137b9f8903
sha512: 0fa9256acf4c58d8de775bb93b90915c308a881ce68134080d31ce1a977e1887335c8dd142a7c021a2de9cfb29845f86d8b3d3057b619fa0ab5f3c9770a5174d
ssdeep: 49152:uK0m5bxELpLhLMsUF1eP9V4bUqlGM1gIXVr:uKbwnL2F8ZMg
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Packed.Themida.Gen.DN also known as:

BkavW32.HfsAutoB.
FireEyeGeneric.mg.b995a3cfedaf936d
McAfeeArtemis!B995A3CFEDAF
CylanceUnsafe
K7AntiVirusTrojan ( 00545bd11 )
K7GWTrojan ( 00545bd11 )
Cybereasonmalicious.4ea7ac
BitDefenderThetaGen:NN.ZexaF.34122.IzXaaWmqYRg
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Miner.astck
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#ufpgxgbgxd58
F-SecureTrojan.TR/Crypt.TPM.Gen
VIPREBackdoor.Win32.Ircbot.gen (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Swizzor.tc
Trapminemalicious.high.ml.score
SentinelOneDFI – Suspicious PE
AviraTR/Crypt.TPM.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmTrojan.Win32.Miner.astck
GDataWin32.Trojan.Agent.AP3SVE
AhnLab-V3HackTool/Win32.GameTool.C3360109
Acronissuspicious
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Packed.Themida.Gen.DN
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazo3zmR5SS0yYtP63XprzCsU)
IkarusTrojan.Win32.Themida
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.e45

How to remove Win32/Packed.Themida.Gen.DN?

Win32/Packed.Themida.Gen.DN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment