Trojan

Trojan.Win32.Vebzenpak.gzm removal

Malware Removal

The Trojan.Win32.Vebzenpak.gzm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vebzenpak.gzm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Vebzenpak.gzm?


File Info:

crc32: EA92F4EB
md5: f41492a72bbc3073991c031139c5507c
name: Ligkistemagasinets_PACKED.exe
sha1: d026739c373eaa516e7c71fc83c752639ac8282b
sha256: aee1c1e032eb65d7d1dfd2e5e114ac5e28ecf5c710ad9b459bb5bb767fd5c033
sha512: 43e86d57e5bf3c182db851f1aba11889ad0f762ac89d11456698b4fabf07a3a85f3ee5b1dcd9f408f5350f11e25d56c6fc810ec686277675b54b93c4a06156c6
ssdeep: 3072:Kry+bnr+O1P5GWp1icKAArDZz4N9GhbkrNEk1cYg5FpHo2:Kry+bnr+cp0yN90QEOg9I
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan.Win32.Vebzenpak.gzm also known as:

MicroWorld-eScanGen:Heur.Crifi.3
FireEyeGen:Heur.Crifi.3
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Heur.Crifi.3
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Heur.Crifi.3
KasperskyTrojan.Win32.Vebzenpak.gzm
AegisLabTrojan.Win32.Crifi.4!c
RisingSpyware.Zbot!8.16B (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.VB.Gen
Invinceaheuristic
EmsisoftGen:Heur.Crifi.3 (B)
WebrootW32.Trojan.Gen
AviraTR/Dropper.VB.Gen
Antiy-AVLTrojan[Backdoor]/MSIL.SpyGate
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Crifi.3
ZoneAlarmTrojan.Win32.Vebzenpak.gzm
ALYacGen:Heur.Crifi.3
MAXmalware (ai score=83)
Ad-AwareGen:Heur.Crifi.3
ESET-NOD32Win32/TrojanDownloader.Agent.EYK
TencentWin32.Trojan.Vebzenpak.Eacq
IkarusTrojan-Spy.Agent
FortinetW32/GenKryptik.EGBI!tr
BitDefenderThetaAI:Packer.04146AB323
Cybereasonmalicious.72bbc3
Qihoo-360Win32/Trojan.910

How to remove Trojan.Win32.Vebzenpak.gzm?

Trojan.Win32.Vebzenpak.gzm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment