Trojan

Trojan.Win32.Zenpak.aicg (file analysis)

Malware Removal

The Trojan.Win32.Zenpak.aicg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.aicg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Trojan.Win32.Zenpak.aicg?


File Info:

crc32: A8028745
md5: e446d71544e8a5a992437944ab17a1f0
name: tmpplsz2pud
sha1: 6b66fca125193f0eb0a6fc53c5d4eb087768ff9c
sha256: 6dd47e1115a474cb900e12016a70ce010128db810c9de6197b129f4fbbac70ae
sha512: 3aa3d58bd8bf8b741a79a6f4463ff124835f9b9d0b393f6e8c0753c21d2a3c3ca612f057b58ee81bee90b8db422a0ca7ed9276ce5b6220fa1d87b2ab6639dbda
ssdeep: 12288:Ihu00jM2wwLHqpVxT85LfHbRhco5QFuo+NmAdIiftnG3:u0jM2wwTX5Ldhf5QUo+NNC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)Qihu 360 Software Co., Ltd. All rights reserved.
InternalName: DeviceMgr
FileVersion: 9,0,0,1002
CompanyName: QIHU 360 SOFTWARE CO. LIMITED
ProductName: 360 Connect
ProductVersion: 9,0,0,1002
FileDescription: 360 Connect
OriginalFilename: DeviceMgr.exe
Translation: 0x0804 0x04b0

Trojan.Win32.Zenpak.aicg also known as:

BkavW32.AIDetectVM.malwareA
MicroWorld-eScanTrojan.Agent.ESWL
FireEyeGeneric.mg.e446d71544e8a5a9
Qihoo-360HEUR/QVM19.1.197B.Malware.Gen
McAfeeGenericRXLC-HC!E446D71544E8
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Agent.ESWL
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataTrojan.Agent.ESWL
KasperskyTrojan.Win32.Zenpak.aicg
RisingTrojan.Kryptik!1.C745 (CLASSIC)
Ad-AwareTrojan.Agent.ESWL
EmsisoftTrojan.Agent.ESWL (B)
TrendMicroBackdoor.Win32.QAKBOT.SME
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
SophosTroj/Qbot-FS
IkarusTrojan.Qakbot
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
Endgamemalicious (high confidence)
ArcabitTrojan.Agent.ESWL
ZoneAlarmTrojan.Win32.Zenpak.aicg
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Trojan/Win32.Qakbot.R341218
Acronissuspicious
ALYacTrojan.Agent.ESWL
VBA32BScope.Trojan.Zenpak
MalwarebytesTrojan.MalPack.SGI
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEHC
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SME
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Cridex.VHO!tr
BitDefenderThetaGen:NN.ZexaF.34128.SM1@aSfRvmpi
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.125193
Paloaltogeneric.ml

How to remove Trojan.Win32.Zenpak.aicg?

Trojan.Win32.Zenpak.aicg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment