Malware

Win32/Packed.Themida.HHT removal guide

Malware Removal

The Win32/Packed.Themida.HHT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.HHT virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 612A8583BB98588AC577C19739083C9F.mlw, GPUCheck.exe
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Packed.Themida.HHT?


File Info:

crc32: BB013D54
md5: 612a8583bb98588ac577c19739083c9f
name: 612A8583BB98588AC577C19739083C9F.mlw
sha1: 691302bec13b179eae5a3633b8c0c9c8cdbe8445
sha256: cecec57f313fb078e7d74e58fe261842db81ad31d61957836ad01859285c3a77
sha512: 6d8de655200f60831cba255676edfa5a7e2a1b5aa729a8150bb1d42fbb5a3d31ddbdbb17313436dfdfb4701c319c482213db8a9c6eadfda792e76a428105666f
ssdeep: 24576:xmmC6JjIIwdZDP9pTezlJywP28CFbSGh6PIu9UyOc3XYWxANqxpLQVuQE:xmmFEIwD79hepEIlGkPIu9U5NMp/QE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Packed.Themida.HHT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f4ef1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic
ALYacGen:Variant.Symmi.93663
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaPacked:Win32/Themida.97a82e55
K7GWTrojan ( 0040f4ef1 )
Cybereasonmalicious.3bb985
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.HHT
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.93663
MicroWorld-eScanGen:Variant.Symmi.93663
TencentWin32.Trojan.Generic.Wkvq
Ad-AwareGen:Variant.Symmi.93663
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34738.AzXaaugpKt
VIPREBackdoor.Win32.Ircbot.gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.612a8583bb98588a
EmsisoftGen:Variant.Symmi.93663 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.TPM.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Tiggre!rfn
GridinsoftTrojan.Heur!.038120A1
ArcabitTrojan.Symmi.D16DDF
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Symmi.93663
AhnLab-V3Trojan/Win32.Black.C1573249
Acronissuspicious
McAfeeArtemis!612A8583BB98
MAXmalware (ai score=81)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CFD21
IkarusTrojan.Win32.Themida
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Packed.Themida.HHT?

Win32/Packed.Themida.HHT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment