Malware

Win32/Packed.Themida.HXI removal

Malware Removal

The Win32/Packed.Themida.HXI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Themida.HXI virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • The following process appear to have been packed with Themida: A8B7FB197929A202AA41091129FC8BF1.mlw
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Packed.Themida.HXI?


File Info:

crc32: 4854AB7A
md5: a8b7fb197929a202aa41091129fc8bf1
name: A8B7FB197929A202AA41091129FC8BF1.mlw
sha1: 9aac742a886eaf567d1dca64ecd6f2b6c8667010
sha256: 1e1a379e4d17d0fc66a4bf0b42d8ff26cca7c0ccc3c452a42a4a21db4aa16467
sha512: ddc3b6d09d4cea20c4fdb2d5d9e700aa46da339a1e2763ce6d4b1bd66bf72a5cad6cbec565685c64da952b49a01dcf4d788ebde9e708a5270e65afae02f791cf
ssdeep: 49152:IfHsaEW0BcUfhB2qiAitKYdXNFWmRBIuAd4Zaq2oRR6E:IfHjqpoFdXXCdPnK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2014-2018 Andrew Sampson
FileVersion: 9.5.6.1328
CompanyName: Andrew Sampson
Comments: This installation was built with Inno Setup.
ProductName: Borderless Gaming
ProductVersion: 9.5.6
FileDescription: Borderless Gaming Setup
Translation: 0x0000 0x04b0

Win32/Packed.Themida.HXI also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057f53f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46626029
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaPacked:Win32/Themida.c1f3047b
K7GWTrojan ( 0057f53f1 )
Cybereasonmalicious.a886ea
CyrenW32/Trojan.YJGG-5578
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.HXI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-PSW.MSIL.Reline.dqz
BitDefenderTrojan.GenericKD.46626029
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanTrojan.GenericKD.46626029
Ad-AwareTrojan.GenericKD.46626029
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34796.jI2@aOY2aoii
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.a8b7fb197929a202
EmsisoftTrojan.GenericKD.46626029 (B)
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Emotet!ml
GridinsoftTrojan.Heur!.012100B1
GDataTrojan.GenericKD.46626029
AhnLab-V3Trojan/Win.Agent.C4553414
Acronissuspicious
McAfeeArtemis!A8B7FB197929
MAXmalware (ai score=80)
VBA32BScope.TrojanDownloader.MSIL.Pasta
TrendMicro-HouseCallTROJ_GEN.R002H07GE21
RisingTrojan.Generic@ML.93 (RDML:eKfJdsr/2LjeKCcOWSmGRw)
IkarusTrojan.Win32.Themida
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.Generic.HgIASYcA

How to remove Win32/Packed.Themida.HXI?

Win32/Packed.Themida.HXI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment