Spy

Spyware.ZeuS.Panda (file analysis)

Malware Removal

The Spyware.ZeuS.Panda is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.ZeuS.Panda virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spyware.ZeuS.Panda?


File Info:

crc32: F58A50CA
md5: 929382d455868a6037c3a4ff93e81314
name: upload_file
sha1: 913fca01c50a2be893f26de347cef21f185de49c
sha256: 70eae6d411554b0587f9bc3e7e7cc753e81b8086310dc5fa8181c44632fe1ada
sha512: cffd02e07e36a79c75f86c1bc3eeed352fb6b2fabe399d88dc2d69dfe9cd829e8888752d2b9b32f54b7ebacfc79b04ecee0f292545a47163ae0703038168cdbe
ssdeep: 6144:+LJeRq3s+SoggtUQg2tHlQNCL0TJd5FjZ0nriipVor1aYtE6gR9KTlkyrcijO:4n3s+3tvdtFCCYV7FjqP81aoblk/ijO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2007, 2008, 2009, 2010, 2011, 2012 Jakub Wilk
FileDescription: PDF to DjVu converter
FileVersion: 0.7.14
Comments: This package is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; version 2 dated June, 1991.
ProductName: pdf2djvu 0.7.14 (DjVuLibre 3.5.25, poppler 0.18.4, GNOME XSLT 1.1.26, GNOME XML 2.7.8)
Translation: 0x0409 0x0000

Spyware.ZeuS.Panda also known as:

MicroWorld-eScanTrojan.GenericKD.34253875
Qihoo-360Generic/HEUR/QVM07.1.E1BD.Malware.Gen
ALYacTrojan.Agent.Zenpak
BitDefenderTrojan.GenericKD.34253875
ArcabitTrojan.Generic.D20AAC33
Invinceaheuristic
SymantecRansom.Wannacry
ESET-NOD32a variant of Win32/Kryptik.HFFW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zenpak.apub
AlibabaBackdoor:Win32/KZip.e4a5c1e3
Ad-AwareTrojan.GenericKD.34253875
EmsisoftMalCert.A (A)
F-SecureTrojan.TR/AD.CobaltStrike.uqvft
DrWebTrojan.DownLoad4.13998
TrendMicroTROJ_FRS.VSNTGT20
FireEyeGeneric.mg.929382d455868a60
SophosMal/Generic-S
IkarusMalware.Win32.CobaltStrike
WebrootW32.Zenpak.apub
AviraTR/AD.CobaltStrike.uqvft
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Ymacco.AA70
ZoneAlarmTrojan.Win32.Zenpak.apub
CynetMalicious (score: 100)
McAfeeArtemis!929382D45586
VBA32BScope.Trojan.Zenpak
MalwarebytesSpyware.ZeuS.Panda
TrendMicro-HouseCallTROJ_FRS.VSNTGT20
RisingTrojan.Zenpak!8.10372 (CLOUD)
SentinelOneDFI – Suspicious PE
GDataWin32.Malware.CobaltStrike.VDY4D9
AVGFileRepMalware
AvastFileRepMalware

How to remove Spyware.ZeuS.Panda?

Spyware.ZeuS.Panda removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment