Trojan

About “Trojan.Win32.Vebzenpak.dnr” infection

Malware Removal

The Trojan.Win32.Vebzenpak.dnr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vebzenpak.dnr virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Vebzenpak.dnr?


File Info:

crc32: 255721B2
md5: 3f0dba61ef9935f67e024e2209135681
name: lastimg.png
sha1: 9de8e84b5d78826a8ef463967e12ecd15eae25a9
sha256: 694cdbab05146adbc035b171e4b301942ab269992ca8ee21198eee2d422dd822
sha512: a9f3c829d088bbd59f62496093fb6bfef551b4e50b73fe1a35441d7a89d32adc39f9f13eb3b17b7b3a364950c13e29f6eb5aed787be6797dd79a3d8a2b537d89
ssdeep: 6144:emohdxrTD9gAdMMntFFX5UxsM+mWn5P7sRI0tJ86OtuGtey:emoxHD9gAdMMtDXm8mWniI0t1OtNtey
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: eCombo
FileVersion: 1.0.0.0
CompanyName: Pro-Friends
ProductName: eCombo
ProductVersion: 1.0.0.0
FileDescription: complimentary control to Priyank Modi's Enhanced
OriginalFilename: eCombo.exe

Trojan.Win32.Vebzenpak.dnr also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Agent.EMDG
FireEyeGeneric.mg.3f0dba61ef9935f6
CylanceUnsafe
SangforMalware
BitDefenderTrojan.Agent.EMDG
Cybereasonmalicious.b5d788
BitDefenderThetaGen:NN.ZevbaF.34090.Nm0@aqAGdrgO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EKQP
GDataTrojan.Agent.EMDG
KasperskyTrojan.Win32.Vebzenpak.dnr
Ad-AwareTrojan.Agent.EMDG
F-SecureTrojan.TR/Injector.zdfur
DrWebTrojan.Trick.46529
McAfee-GW-EditionBehavesLike.Win32.Trojan.jh
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.EMDG (B)
APEXMalicious
WebrootW32.Trojan.Gen
AviraTR/Injector.zdfur
Endgamemalicious (high confidence)
ArcabitTrojan.Agent.EMDE
ZoneAlarmTrojan.Win32.Vebzenpak.dnr
MAXmalware (ai score=81)
PandaTrj/TrickBot.A
RisingTrojan.Injector!8.C4 (C64:YzY0OjGa/44YNH26)
FortinetW32/Injector.EKQP!tr
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Win32.Vebzenpak.dnr?

Trojan.Win32.Vebzenpak.dnr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment