Trojan

What is “Trojan.Win32.Vebzenpak.zdg”?

Malware Removal

The Trojan.Win32.Vebzenpak.zdg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vebzenpak.zdg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a JPG image by having ‘jpg’ in the file name.
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Vebzenpak.zdg?


File Info:

crc32: BA47714A
md5: 1b6b8763e2d0626c25905fc77cd21d1e
name: Me.jpg.jpg.jpg.scr
sha1: 0001ed9c88ddc73ad5aa1344d9ffe0239eaa5a97
sha256: ab58aec6825baf6f83a0c3de3553dd1b727934bcdbb05f6644122911a514f079
sha512: 12ffa12b470b956da04835ded2dd28a99df821862724275dc87d34a1085d0b0d8b47e64c5aa211cb87a963c1d9ce9d1c44664307e340c798808be27dc7137759
ssdeep: 768:xpM9L79mPJ7eruB60qWHa4pd8K2ytu1uxpNGku1JiB8dR04N6DzP6tDHZn1Z0m:xybmt40I4Ibwu1WpkiBcR0BCbYm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: ISKLUMP
InternalName: Mercurialism7
FileVersion: 1.00
LegalTrademarks: Kommandofortolkere
ProductName: Sommerboliger
ProductVersion: 1.00
OriginalFilename: Mercurialism7.exe

Trojan.Win32.Vebzenpak.zdg also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.248325
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Strictor.248325
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056c5881 )
BitDefenderGen:Variant.Strictor.248325
K7GWTrojan ( 0056c5881 )
Cybereasonmalicious.c88ddc
CyrenW32/Kryptik.BTV.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EMZA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vebzenpak.zdg
AlibabaTrojan:Win32/Vebzenpak.f5b72f01
NANO-AntivirusTrojan.Win32.Vebzenpak.hryfop
AvastWin32:Trojan-gen
TencentWin32.Trojan.Vebzenpak.Dzkl
Ad-AwareGen:Variant.Strictor.248325
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1109934
DrWebTrojan.Siggen10.4231
TrendMicroTROJ_GEN.R002C0DHF20
FireEyeGeneric.mg.1b6b8763e2d0626c
SophosMal/Generic-S
F-ProtW32/Kryptik.BTV.gen!Eldorado
eGambitUnsafe.AI_Score_98%
AviraHEUR/AGEN.1109934
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Guloader.VB!MTB
ZoneAlarmTrojan.Win32.Vebzenpak.zdg
GDataGen:Variant.Strictor.248325
CynetMalicious (score: 90)
McAfeeFareit-FYM!1B6B8763E2D0
MalwarebytesTrojan.MalPack.VB
TrendMicro-HouseCallTROJ_GEN.R002C0DHF20
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.105305972.susgen
FortinetW32/EMZA!tr
BitDefenderThetaGen:NN.ZevbaF.34186.gm0@aKSx!Alb
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.1da

How to remove Trojan.Win32.Vebzenpak.zdg?

Trojan.Win32.Vebzenpak.zdg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment