Malware

How to remove “Win32/Packed.Themida.HKI”?

Malware Removal

The Win32/Packed.Themida.HKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.HKI virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
shar2345ewater.space
a.tomx.xyz
iplogger.org
www.bing.com

How to determine Win32/Packed.Themida.HKI?


File Info:

crc32: D95F67DD
md5: 3969e69b8b47519be7c5d711ad6407f3
name: spedup1.exe
sha1: e1494e1ec440883e8a460da171026beff6f14e50
sha256: 864c6fe05a621e36a32b63b68892ecbdeb4c971f8673ed23a0a83bb2b9d770a7
sha512: 647c6083adc9268bc34a2445ce965be8552ac7a43f27e600f2283651a9ba6d902dc8ea090d79afe8a419db0d59fba980ed99a7b6558aeb62d0a5a19d6ec299e2
ssdeep: 98304:ZQMQhDbQKrYrfW/V8qd+bZO5LWcIdgfnJYWXwlYOUsB7asnfoHIMmbaF/c/+FQoc:9ybRYrG8qd+bg5LWx2PeWXaYSeVoFbac
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Speedup inc
Comments: This installation was built with Inno Setup.
ProductName: Speedup
ProductVersion: 4.8
FileDescription: Speedup Setup
Translation: 0x0000 0x04b0

Win32/Packed.Themida.HKI also known as:

DrWebTrojan.PWS.Steam.18005
MicroWorld-eScanGen:Variant.Ursu.795233
Qihoo-360HEUR/QVM06.1.5D29.Malware.Gen
ALYacGen:Variant.Ursu.795233
BitDefenderGen:Variant.Ursu.795233
AvastWin32:Malware-gen
GDataGen:Variant.Ursu.795233
KasperskyTrojan.Win32.Zenpak.yfy
Ad-AwareGen:Variant.Ursu.795233
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1042347
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
EmsisoftGen:Variant.Ursu.795233 (B)
IkarusTrojan.MSIL.Agent
JiangminTrojan.PSW.Kpot.bi
WebrootW32.Adware.Gen
AviraTR/Zenpak.ouvlf
ArcabitTrojan.Ursu.DC2261
ZoneAlarmTrojan.Win32.Zenpak.yfy
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Trojan/Win32.Agent.C4014674
McAfeeArtemis!3969E69B8B47
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Themida.HKI
AVGWin32:Malware-gen

How to remove Win32/Packed.Themida.HKI?

Win32/Packed.Themida.HKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment