Trojan

About “Trojan.Win32.Zenpak.bbuq” infection

Malware Removal

The Trojan.Win32.Zenpak.bbuq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.bbuq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Zenpak.bbuq?


File Info:

crc32: 79468B84
md5: 563b1d1769a976a582cbe8d2857dd67d
name: 563B1D1769A976A582CBE8D2857DD67D.mlw
sha1: 398ab27c3beffae3759e410b898d8b83552ed685
sha256: 9fb99b21954b4143b496e0fcb64e4fc6ee73d86af984f5252d0faa0ca2a3e68c
sha512: bb87f7ddccf8ad39ab54302c5fb954b0caa85f8bf305f7ae2e14c6f58ac9b0496ee37a89c96d051dc0cb028be87f795ac40fa9e8cc8e38516d85b4c0844cc458
ssdeep: 98304:CsZnjRbpHSh2isZxukQivkCxX2EAuZuNVcb3eZqZa2DnUZLxT3n+cokk3Q+jM9Z:CUTA25QywEX6eUr/hlk3BCt0tZh
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Product: 1.7.8
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationz

Trojan.Win32.Zenpak.bbuq also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.56760
MicroWorld-eScanTrojan.GenericKD.35911685
FireEyeGeneric.mg.563b1d1769a976a5
McAfeeArtemis!563B1D1769A9
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35911685
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c3beff
BitDefenderThetaGen:NN.ZexaF.34700.@pGfaS00Bwgc
CyrenW32/Kryptik.CVF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan.Win32.Zenpak.bbuq
AlibabaBackdoor:Win32/Zenpack.8f9e246c
TencentWin32.Trojan.Zenpak.Sued
Ad-AwareTrojan.GenericKD.35911685
EmsisoftTrojan.GenericKD.35911685 (B)
F-SecureTrojan.TR/AD.GoCloudnet.uumsa
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_96%
AviraTR/AD.GoCloudnet.uumsa
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Kryptik.vb
ArcabitTrojan.Generic.D223F805
ZoneAlarmTrojan.Win32.Zenpak.bbuq
GDataTrojan.GenericKD.35911685
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R360985
Acronissuspicious
VBA32Trojan.Glupteba
ALYacTrojan.GenericKD.35911685
MalwarebytesTrojan.MalPack.GS
PandaTrj/Agent.ALS
ESET-NOD32a variant of Win32/Kryptik.HILM
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HGHW!tr
WebrootW32.Trojan.Gen
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.37EF.Malware.Gen

How to remove Trojan.Win32.Zenpak.bbuq?

Trojan.Win32.Zenpak.bbuq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment