Trojan

What is “Trojan.Win32.Zenpak.biwa”?

Malware Removal

The Trojan.Win32.Zenpak.biwa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.biwa virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Enumerates running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a command line with /V argument which modifies variable behaviour and whitespace allowing for increased obfuscation options
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine Trojan.Win32.Zenpak.biwa?


File Info:

name: 1C8A286C4928BFDD3207.mlw
path: /opt/CAPEv2/storage/binaries/48c015e6897d8be6110ba5793d3a4139a4116c21db34674cb67b75685c4803e7
crc32: 35BCF529
md5: 1c8a286c4928bfdd3207076076ac5e2d
sha1: 8f0b1b7e9b0afb6be1c329e715c756440585bef9
sha256: 48c015e6897d8be6110ba5793d3a4139a4116c21db34674cb67b75685c4803e7
sha512: a91323c0c84a7b4d7ab7432bf65659a508ef66a7a92c0f72cd5d4b1830dc45fd2e7ed37c5eab482b41176134e0798eace6b3238eb415541fc824bb35fe72c35b
ssdeep: 6144:SdS5e/5DXMGswDkLLKYzOZOurN5qBvvHEPA1181cNinnexg7uFmoPbT42lhsREo9:SdXxTMGsMEzOL5q9HEP57o94AhuHQ3q
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T171D49E86F3E468F5D067D13989928746E27278284B3183CB13A1971E7F376E19D3EB20
sha3_384: 07b9053e5ce316dba17ce4e0f0ad6409c0cc80dfd54847a87e7b1c21bb7f2b6aad1e5e0c1d0dd749a3ffd3f44b17475e
ep_bytes: 4883ec28e8378800004883c428e9fefc
timestamp: 2020-12-07 16:35:29

Version Info:

CompanyName: Tarh Afarinan Sepahan(TASoft)
FileDescription: Test Application for CSelectDialog class
FileVersion: 1.0.0.1
InternalName: SelectDialogTest.exe
LegalCopyright: Copyright (c) Tarh Afarinan Sepahan (TASoft) Co Ltd. All rights reserved.
LegalTrademarks: www.TarhAfarinan.ir
OriginalFilename: SelectDialogTest.exe
ProductName: CSelectDialog Tester
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Trojan.Win32.Zenpak.biwa also known as:

LionicTrojan.Win32.Bazdor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38184031
FireEyeGeneric.mg.1c8a286c4928bfdd
ALYacTrojan.GenericKD.38184031
K7AntiVirusTrojan ( 0057538b1 )
BitDefenderTrojan.GenericKD.38184031
K7GWTrojan ( 0057538b1 )
ESET-NOD32a variant of Win64/Kryptik.CEE
TrendMicro-HouseCallTROJ_GEN.R002H0DL421
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zenpak.biwa
AlibabaTrojan:Win32/Zenpak.e9253c03
Ad-AwareTrojan.GenericKD.38184031
McAfee-GW-EditionRDN/Generic BackDoor
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Shelma.guw
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D246A45F
GDataTrojan.GenericKD.38184031
CynetMalicious (score: 100)
McAfeeRDN/Generic BackDoor
IkarusTrojan.Win64.Crypt
PandaTrj/CI.A
FortinetPossibleThreat.MU
AVGWin64:Trojan-gen
AvastWin64:Trojan-gen

How to remove Trojan.Win32.Zenpak.biwa?

Trojan.Win32.Zenpak.biwa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment