Malware

What is “Win32/Packed.Themida.HDC”?

Malware Removal

The Win32/Packed.Themida.HDC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.HDC virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempted to write directly to a physical drive

How to determine Win32/Packed.Themida.HDC?


File Info:

name: 384788178EC3015416CC.mlw
path: /opt/CAPEv2/storage/binaries/1f854ab77780b807ae05dbb0c0212988e250ba500d895e89cdae578ee547ebd2
crc32: 07315B9E
md5: 384788178ec3015416cc830fd3f63ed0
sha1: e6b8b18944523244aff26127b7d68286e70fb119
sha256: 1f854ab77780b807ae05dbb0c0212988e250ba500d895e89cdae578ee547ebd2
sha512: 73fc29536a1132028f71b1c98ac652d206435caaaf0b87c51826f127a37125a1f75399e4489ab08dffeb419c32721928844450ba3d89bae9df0e553ad7cfd995
ssdeep: 49152:6uxP0dFXklf3Muj8mbCz6ZiNygJ71qBEoYSRBOPmFn:6uxP0dlMf3Muj8mg6Uya1qBETSRBOAn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137F54C627509E2DFD19725789423CD469ABD83F94B158CC39C2CB4F9AE23CC125F9E28
sha3_384: 4d0869bae9db986b78aa97df7b7125a0ea83827c58ad5358dbb83c86374b2957d322c8c37522860cfaff98ead7a2173b
ep_bytes: 565053e801000000cc5889c3402d0000
timestamp: 2018-02-08 01:42:02

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: MRSnapzNet
FileDescription: MRSnapzNet
FileVersion: 1.0.0.0
InternalName: MRSnapzNet.exe
LegalCopyright: Copyright © MRSnapzNet Gaming 2018
LegalTrademarks:
OriginalFilename: MRSnapzNet.exe
ProductName: MRSnapzNet
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Win32/Packed.Themida.HDC also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Phpw.1!c
FireEyeGeneric.mg.384788178ec30154
McAfeeArtemis!384788178EC3
CylanceUnsafe
AlibabaRiskWare:Win32/Themida.de852745
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34294.lx0@a0JXySb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.HDC
TrendMicro-HouseCallTROJ_GEN.R002H0CKI21
Paloaltogeneric.ml
Kasperskynot-a-virus:RiskTool.Win32.Phpw.bpx
NANO-AntivirusTrojan.Win32.Razy.exuzel
AvastWin32:Malware-gen
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
SophosGeneric PUA OG (PUA)
IkarusPUA.Themida
GDataWin32.Trojan.Agent.QAFACI
MicrosoftTrojan:Win32/Occamy.C1F
Acronissuspicious
VBA32BScope.Trojan.Downloader
APEXMalicious
YandexRiskware.Themida!dp8tWpWCkkI
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic_PUA_OG
AVGWin32:Malware-gen
Cybereasonmalicious.944523
PandaTrj/CI.A

How to remove Win32/Packed.Themida.HDC?

Win32/Packed.Themida.HDC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment