Trojan

What is “Trojan.Win32.Zenpak.bbzv”?

Malware Removal

The Trojan.Win32.Zenpak.bbzv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.bbzv virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Zenpak.bbzv?


File Info:

crc32: 161FEF78
md5: 658143011e89a6a102b025dec25c31c8
name: 658143011E89A6A102B025DEC25C31C8.mlw
sha1: 1bdade4e895786ac55d0ef3a0d69ab588f8dfb9e
sha256: 10f0322c97ab67ef1111090501073f2eeef8b7e6ce1247d1ec141c7ba2018e10
sha512: 6d34382f39392f74d801be2d0ae5a86a5230951fe74ec8b63f4e307adfb3d42ed6756bf61acdaa976ff82e7efc9060e20a1c84e18aa3c5b7bde2039ed87b4659
ssdeep: 98304:I3yxFAxCMdWhRqHqDHf5ieyTrvqMnn2hbHCG4cNTRBi1otdYq1LNX/Ff4nad2BY:7AUhYHq6b3mzGKFgadpW02yuTj/xYYF
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVers: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationzi

Trojan.Win32.Zenpak.bbzv also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35921713
FireEyeGeneric.mg.658143011e89a6a1
McAfeeArtemis!658143011E89
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005756a31 )
BitDefenderTrojan.GenericKD.35921713
K7GWTrojan ( 005756a31 )
Cybereasonmalicious.e89578
BitDefenderThetaGen:NN.ZexaF.34700.@pGfaSdxgTn
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zenpak.bbzv
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
Ad-AwareTrojan.GenericKD.35921713
SophosMal/Generic-S
F-SecureTrojan.TR/AD.GoCloudnet.aexek
DrWebTrojan.Siggen11.56879
TrendMicroTROJ_FRS.VSNTLT20
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Krypt
AviraTR/AD.GoCloudnet.aexek
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Zenpack.MU!MTB
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D2241F31
ZoneAlarmTrojan.Win32.Zenpak.bbzv
GDataTrojan.GenericKD.35921713
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4283300
Acronissuspicious
ALYacTrojan.GenericKD.35921713
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HILV
TrendMicro-HouseCallTROJ_FRS.VSNTLT20
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_59%
FortinetW32/Kryptik.GWQD!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.409B.Malware.Gen

How to remove Trojan.Win32.Zenpak.bbzv?

Trojan.Win32.Zenpak.bbzv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment