Trojan

How to remove “Trojan.Win32.Zenpak.bchy”?

Malware Removal

The Trojan.Win32.Zenpak.bchy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.bchy virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:17717
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Trojan.Win32.Zenpak.bchy?


File Info:

crc32: 883AA1D7
md5: c55a1a3a135dcc3a771ea4648862a202
name: C55A1A3A135DCC3A771EA4648862A202.mlw
sha1: 7c156e5701b0cf7eaf3a38cc1f5f68992bfe62f8
sha256: c0eb802f394e758da4feb0d6c3b817bf1f64880ab9bc851937d5ef774161585d
sha512: c1254cad4d620b96a2a620ef54a3c6391a3ddfece27819348cac5166489f788b827828f227c2dd5f893152d5c591eb1f63cfe14e99ad098f14b5b9ff59fce521
ssdeep: 98304:4OtxgEKjQcf+Hdzbfd56/kzkv6iS+KZHQ029ETbnsFaK0ua1fe1NjmWkiYi5FE9:4kgdjDazrP6szkvqwl3aK09fUVHZSo6
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafuck
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Trojan.Win32.Zenpak.bchy also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35969491
CAT-QuickHealTrojan.Glupteba
ALYacSpyware.Danabot.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 00575b3b1 )
BitDefenderTrojan.GenericKD.35969491
K7GWTrojan ( 00575b3b1 )
Cybereasonmalicious.a135dc
ArcabitTrojan.Generic.D224D9D3
CyrenW32/Trojan.GLRN-2958
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.FickerStealer-9819303-1
KasperskyTrojan.Win32.Zenpak.bchy
AlibabaBackdoor:Win32/Glupteba.99c3622d
ViRobotTrojan.Win32.Z.Zenpak.4591616
TencentWin32.Trojan.Zenpak.Sxeg
Ad-AwareTrojan.GenericKD.35969491
EmsisoftTrojan.GenericKD.35969491 (B)
ComodoMalware@#3iy7an4g11fyl
F-SecureTrojan.TR/Zenpak.ukezf
DrWebTrojan.MulDrop16.9917
ZillyaTrojan.Zenpak.Win32.5492
TrendMicroTROJ_GEN.R002C0DA521
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.c55a1a3a135dcc3a
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Zenpak.ukezf
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.Kryptik.hiry
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.NW!MTB
ZoneAlarmTrojan.Win32.Zenpak.bchy
GDataTrojan.GenericKD.35969491
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361868
Acronissuspicious
McAfeeArtemis!C55A1A3A135D
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIOC
TrendMicro-HouseCallTROJ_GEN.R002C0DA521
RisingTrojan.Kryptik!8.8 (TFE:5:beSYtboWWOS)
IkarusTrojan.MalPack
eGambitUnsafe.AI_Score_50%
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34780.@pKfaGSQWXkG
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM11.1.540F.Malware.Gen

How to remove Trojan.Win32.Zenpak.bchy?

Trojan.Win32.Zenpak.bchy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment