Trojan

What is “Trojan.Win32.Pakes.atzb”?

Malware Removal

The Trojan.Win32.Pakes.atzb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Pakes.atzb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the ZeusPanda malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Pakes.atzb?


File Info:

name: 27EF0D565B8A125806FC.mlw
path: /opt/CAPEv2/storage/binaries/ea05b0aff29ff657a578eed301f79a2ae7a469cda10030151426eff85b2390ea
crc32: 7EDE1195
md5: 27ef0d565b8a125806fc0811c8eddd48
sha1: e023d169ae10e19f24a260ff2e8d0b7b8c1ba2e2
sha256: ea05b0aff29ff657a578eed301f79a2ae7a469cda10030151426eff85b2390ea
sha512: b5e30c0694f78740a62266e2caf0c7814cf9d567e057c43fe3ed2fb4f83c0d5a96ab6fff962596b6c2d3fdaab54349dfc8ae11f24e87724f4244b4ced0f9d0a2
ssdeep: 3072:IZxqAbHOxcuv7R/qZ3BytuyjtCFjBdTuXizMYb+ZPLRtH4c:qq9xcu/PxtCxBEg+DjH4c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB246A9FBA7E4C52E44927B6048A2B22E277EE93055E4A074343777D0D3FE50BF6610A
sha3_384: 51314e18b1c787856e0e1fa344e3544b4b79177ee48d9fb5c6fa8a073327f355d005687c87c38a07923589d8918b765b
ep_bytes: 68b8594000e8eeffffff000000000000
timestamp: 2016-12-13 19:43:09

Version Info:

Translation: 0x0409 0x04b0
Comments: flap commonly used in reconstruction of facial skin defects. The bilobed flap allows for the movement ...
CompanyName: flasH lap commonly used in reconstruction of facial skin defects. The bilobed flap allows for the movement ...
FileDescription: lap commonly used in reconstruction of facial skin defects. The bilobed flap allows for the movement ...
LegalCopyright:
LegalTrademarks:

Trojan.Win32.Pakes.atzb also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Pakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.38436
MicroWorld-eScanTrojan.GenericKD.3880196
FireEyeGeneric.mg.27ef0d565b8a1258
CAT-QuickHealTrojan.VBCrypt.MF.6643
ALYacTrojan.GenericKD.3880196
CylanceUnsafe
ZillyaTrojan.Pakes.Win32.39835
SangforTrojan.Win32.Pakes.atzb
K7AntiVirusSpyware ( 004dc4921 )
AlibabaTrojanSpy:Win32/Pakes.aa706b7b
K7GWSpyware ( 004dc4921 )
Cybereasonmalicious.65b8a1
BitDefenderThetaGen:NN.ZevbaF.34212.nm3@aeWbc1ki
VirITTrojan.Win32.Banker.CAD
CyrenW32/Zbot.ZGIE-5169
SymantecRansom.Kovter
ESET-NOD32Win32/Spy.Zbot.ACM
TrendMicro-HouseCallTSPY_ZBOT.YUYAUM
AvastWin32:Malware-gen
ClamAVWin.Dropper.Mansabo-6611665-0
KasperskyTrojan.Win32.Pakes.atzb
BitDefenderTrojan.GenericKD.3880196
NANO-AntivirusTrojan.Win32.Pakes.eoponj
TencentWin32.Trojan.Pakes.Htwp
Ad-AwareTrojan.GenericKD.3880196
EmsisoftTrojan.GenericKD.3880196 (B)
ComodoMalware@#gerpag0hp9t1
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.YUYAUM
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-R + Troj/VB-JJF
Paloaltogeneric.ml
GDataWin32.Trojan.Agent.Y6M7LT
JiangminTrojan.Pakes.anp
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.VB.nvmab
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AhnLab-V3Trojan/Win32.Inject.R191993
McAfeePWSZbot-FHN.a
MAXmalware (ai score=100)
VBA32Trojan.Pakes
APEXMalicious
RisingSpyware.Zbot!8.16B (C64:YzY0OmTujAUYxrGv)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.ACM!tr.spy
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
PandaTrj/WLT.C
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Pakes.atzb?

Trojan.Win32.Pakes.atzb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment