Trojan

Trojan.Pandex.AA (file analysis)

Malware Removal

The Trojan.Pandex.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Pandex.AA virus can do?

  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Pandex.AA?


File Info:

name: EB4C1F400FCE4968BEBC.mlw
path: /opt/CAPEv2/storage/binaries/a3fa898ff67d86539051c09a518f19a82b516dd5fc6aa173dc3f266a3a187c6f
crc32: E8531AE2
md5: eb4c1f400fce4968bebc36ace5469741
sha1: 990492d3f516d9c4e60c46ea2947cec1013e3d23
sha256: a3fa898ff67d86539051c09a518f19a82b516dd5fc6aa173dc3f266a3a187c6f
sha512: 7be470823a21e9b81ea5835d6e4767d0080b84f95c27fdb3a3070d7a6e0c0852cfb64f9c1ac0732bcc3dcfc666d40250a6df70eb7c2139590d6773aa2c9e1403
ssdeep: 1536:wB97/WIHGlSMft1kRqIrQf3QeiswNQwfpZk+W:wB5/WIHGff6bsXAQwV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3836CA5E3E2807CF8F756314A714667DEBA7D102935D21E96E24B5D0F32AB0D43A383
sha3_384: 1740cae902b5933251adc6d9240b989bcbea7638fa5b27c50e501e7d5a02feedeeba364e6580cca0d7e8ff97db72f078
ep_bytes: 9c579c5233d687edba01a70cbc5a9d81
timestamp: 2007-10-07 02:42:11

Version Info:

0: [No Data]

Trojan.Pandex.AA also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.Pandex.AA
ClamAVWin.Malware.Zbot-9951822-0
FireEyeGeneric.mg.eb4c1f400fce4968
ALYacTrojan.Pandex.AA
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.217389
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052ea4e1 )
K7GWTrojan ( 0052ea4e1 )
Cybereasonmalicious.00fce4
CyrenW32/S-01991af8!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Zbot.ADF
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.o
BitDefenderTrojan.Pandex.AA
NANO-AntivirusVirus.Win32.Gen-Resident.ccnd
AvastWin32:JunkPoly [Cryp]
TencentMalware.Win32.Gencirc.10d09fb6
Ad-AwareTrojan.Pandex.AA
SophosMal/Zbot-K
DrWebTrojan.Packed.201
VIPRETrojan.Pandex.AA
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Pandex.AA (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Pandex.AA
JiangminTrojanSpy.Agent.cvu
WebrootW32.Trojan.Pandex
AviraTR/Spy.Agent.nfg
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.DF
MicrosoftVirTool:Win32/CeeInject.AAP!bit
GoogleDetected
AhnLab-V3Win-Trojan/Hupe.Gen
McAfeePacked-FFP!EB4C1F400FCE
VBA32TScope.Malware-Cryptor.SB
MalwarebytesZbot.Trojan.Stealer.DDS
RisingTrojan.Kryptik!1.B598 (CLASSIC)
YandexPacked/ZCrypt
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Packed.Krap.O
FortinetW32/Kryptik.BVDT!tr
BitDefenderThetaAI:Packer.9B3ADBA41F
AVGWin32:JunkPoly [Cryp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Pandex.AA?

Trojan.Pandex.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment