Malware

Win32/Packed.Themida.Gen.RB information

Malware Removal

The Win32/Packed.Themida.Gen.RB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.Gen.RB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 3056FAD1CF0F2C1740966FC845A88785.mlw
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Win32/Packed.Themida.Gen.RB?


File Info:

crc32: 621B697D
md5: 3056fad1cf0f2c1740966fc845a88785
name: 3056FAD1CF0F2C1740966FC845A88785.mlw
sha1: 79f6a6f6691a1be2cc941758bc56076ae0ab2d25
sha256: 5fcc9ec332ad08ba906d5ed6d30fd9d3a691dc648e2075f7864801890fc742c6
sha512: 0533fa980a60cb08a6225e6c5f60005a2d0567226460e5a5f98d84fd32c28d1dc6609585565bdf17cce5f29ccbdb8c501afccec731bd495e921bae6a12f0ee4b
ssdeep: 12288:NAJ8U6foMIGlt7nfyjNfD386N2ZGJMQe/cnnpqPZ8+rPqVo8zmAHXxzhCA7lrBuB:nDIiRyDDbmH8EPZ8wqVHDCitu3ZAY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1996-2003
InternalName: Half-Life Launcher
FileVersion: 1, 1, 1, 1
CompanyName: Valve
ProductName: Steam Half-Life Launcher
ProductVersion: 1, 1, 1, 1
FileDescription:
OriginalFilename: hl.exe
Translation: 0x0409 0x04b0

Win32/Packed.Themida.Gen.RB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056f8cf1 )
LionicTrojan.Win32.Vasal.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.30100
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.34594904
CylanceUnsafe
ZillyaTrojan.Vasal.Win32.355
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Vasal.9bb0eb0a
K7GWTrojan ( 0056f8cf1 )
Cybereasonmalicious.1cf0f2
CyrenW32/Trojan.YSEZ-2905
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.Gen.RB
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Vasal.byf
BitDefenderTrojan.GenericKD.34594904
NANO-AntivirusTrojan.Win32.Vasal.hxlxhy
MicroWorld-eScanTrojan.GenericKD.34594904
TencentWin32.Trojan.Vasal.Lgti
Ad-AwareTrojan.GenericKD.34594904
SophosMal/Generic-S
ComodoMalware@#1yh7w6b6ffatd
F-SecureTrojan.TR/Vasal.pdgkf
BitDefenderThetaGen:NN.ZexaF.34590.1y0aa0sqY3fi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.3056fad1cf0f2c17
EmsisoftTrojan.GenericKD.34594904 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Vasal.ao
WebrootW32.Malware.Gen
AviraTR/Vasal.pdgkf
eGambitTrojan.Generic
Antiy-AVLTrojan/Win32.Vasal
MicrosoftTrojan:Win32/Ymacco.AA32
GridinsoftTrojan.Heur!.038100A1
ArcabitTrojan.Generic.D20FE058
ZoneAlarmTrojan.Win32.Vasal.byf
GDataTrojan.GenericKD.34594904
AhnLab-V3Trojan/Win32.RL_MSIL.R354271
McAfeeRDN/Generic.rp
MAXmalware (ai score=85)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack.Themida
PandaTrj/CI.A
RisingTrojan.Vasal!8.F509 (CLOUD)
YandexTrojan.Themida!SpgpOarI6cU
IkarusTrojan.Win32.Themida
MaxSecureTrojan.Malware.73900177.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOgA

How to remove Win32/Packed.Themida.Gen.RB?

Win32/Packed.Themida.Gen.RB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment