Malware

What is “Win32/Packed.Themida.HUW”?

Malware Removal

The Win32/Packed.Themida.HUW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.HUW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Win32/Packed.Themida.HUW?


File Info:

crc32: E1670881
md5: 45d5178b6499455359e42e1805de1fbd
name: 45D5178B6499455359E42E1805DE1FBD.mlw
sha1: f9083b8356085de5625436bdb8386ad54e9cc134
sha256: 6e1831e748607edd5d4aeae00af2911061b0e9ca54a1e984807820559b793f66
sha512: 622cb3ae40331bdb6c7c889d449064af6af0d484e4a4685f141d200551bd21efb22ac1163a9b3e51bb1b49b9b93871af3f2c00df0b84ea814fead89f1f084016
ssdeep: 98304:ENX5O3+XrvRW6upuejrV0B5m9fqpk1KBc9kRR:eA+rvRWTpzmDe51KBc9AR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Halogen.exe
FileVersion: 0.0.0.0
Comments: Modified by an unpaid evaluation copy of Resource Tuner Console 2. http://www.heaventools.com
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Halogen.exe
Translation: 0x0000 0x04b0

Win32/Packed.Themida.HUW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057c9901 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Hynamer
ALYacGen:Variant.Razy.628613
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Reline.ef2ae347
K7GWTrojan ( 0057c9901 )
Cybereasonmalicious.b64994
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.HUW
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan-PSW.MSIL.Reline.bxo
BitDefenderGen:Variant.Razy.628613
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.628613
Ad-AwareGen:Variant.Razy.628613
SophosMal/Generic-S
ComodoMalware@#2ht7yxdvpoh53
BitDefenderThetaGen:NN.ZexaF.34722.@B0@aSuup0di
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WF721
McAfee-GW-EditionBehavesLike.Win32.Trojan.rh
FireEyeGeneric.mg.45d5178b64994553
EmsisoftGen:Variant.Razy.628613 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Redcap.owonx
eGambitUnsafe.AI_Score_97%
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
GridinsoftTrojan.Heur!.030100A1
AegisLabTrojan.Win32.Razy.4!c
GDataGen:Variant.Razy.628613
AhnLab-V3Malware/Gen.RL_Reputation.R365609
Acronissuspicious
McAfeeGenericRXAA-AA!45D5178B6499
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1562734577
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CF421
IkarusTrojan.Win32.Themida
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PackedThemida.HJX!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Packed.Themida.HUW?

Win32/Packed.Themida.HUW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment