Trojan

Trojan.Win32.Zenpak.bbus removal tips

Malware Removal

The Trojan.Win32.Zenpak.bbus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.bbus virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
leatherbond.top

How to determine Trojan.Win32.Zenpak.bbus?


File Info:

crc32: 2E2F4D27
md5: 0c4e32c6adfd5de13ecfaccb462cb5f9
name: 0C4E32C6ADFD5DE13ECFACCB462CB5F9.mlw
sha1: 2ab3571f7449baadb3d7bfbe99bc7aface8cc42c
sha256: 71aaff890e5c76962463e4f1c102819a6f7469e76139b5b49282f5f596d7ea36
sha512: 016bc8623945a45d44cae5ff8bc822a7ebc1d84dcc46691fd523f612aeb5802a16db875425d4542ed98ec2bac97cb8227c940154bd511f6a12797c10c5b5e532
ssdeep: 12288:6OgVxj3MQDEyDjwWt9MwedzSMgqcKbYK7VyEoN3ymxlaFJZJn:0VxDMQDvkzrLcKbYQMbymxlaFJZR
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Product: 1.7.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationz

Trojan.Win32.Zenpak.bbus also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35898365
FireEyeGeneric.mg.0c4e32c6adfd5de1
ALYacTrojan.GenericKD.35898365
MalwarebytesTrojan.MalPack.GS
AegisLabTrojan.Win32.Zenpak.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35898365
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f7449b
CyrenW32/Kryptik.CVF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan.Win32.Zenpak.bbus
AlibabaBackdoor:Win32/Zenpack.70df1934
TencentWin32.Trojan.Zenpak.Gcc
Ad-AwareTrojan.GenericKD.35898365
SophosMal/Generic-S
ComodoMalware@#1z4uj5teg9b9p
F-SecureTrojan.TR/Crypt.Agent.qqfad
DrWebTrojan.MulDrop16.3346
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.hc
EmsisoftTrojan.GenericKD.35898365 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Agent.dbjb
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.qqfad
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MT!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D223C3FD
ZoneAlarmTrojan.Win32.Zenpak.bbus
GDataTrojan.GenericKD.35898365
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4282432
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=84)
VBA32Trojan.Agent
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILM
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
FortinetW32/Kryptik.HGHW!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Win32.Zenpak.bbus?

Trojan.Win32.Zenpak.bbus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment