About “Trojan.Win32.Zenpak.pef” infection

Malware Removal

The Trojan.Win32.Zenpak.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Review

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Trojan.Win32.Zenpak.pef virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

www.ip-adress.com

How to determine Trojan.Win32.Zenpak.pef?


File Info:

crc32: 87A74B47
md5: aaad1bbb21a6fb895da375003f342b4f
name: 444444.png
sha1: 4cb3936648a1d84d0908e4a1391c5947c41b4871
sha256: 4ad74b122a447d38d196235c12f50ccf5fb498dc2bd36786dea0558bda4032c8
sha512: ebc700263e6f4682c20e055939ed5530cdec279400fb23613362b7c1d5b94a7da627bf6bd4eb2201ccdee4b9f9698f0a6549c369d3a204b51404c73691ab42fe
ssdeep: 6144:PmZ6ygLi1o2jYsDoEFR4o/kbgUwV3wjwLe0mvefkQAh7InobFr:PmZ+iK2MuhR0gzV3da0mGDAh7InobV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright(c) 2007 Corel Corporation
InternalName: CorelDrw
FileVersion: 14.0.0.701
CompanyName: Corel Corporation
Built on: Fri 11/21/2008 21:36:24.30
LegalTrademarks: Corel, CorelDRAW, Corel DESIGNER, Corel R.A.V.E., Corel PHOTO-PAINT, CorelTRACE and Corel CAPTURE are trademarks or registered trademarks of Corel Corporation and/or its subsidiaries in Canada, the U.S. and/or other countries.
ProductName: Corel Graphics Applications
Language Build ID: 0
ProductVersion: 14.0.0.701
FileDescription: CorelDRAW(R)
OriginalFilename: CorelDrw.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Zenpak.pef also known as:

MicroWorld-eScanTrojan.GenericKDZ.67171
McAfeeW32/PinkSbot-GS!AAAD1BBB21A6
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.67171
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.648a1d
TrendMicroBackdoor.Win32.QAKBOT.SMP1
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataTrojan.GenericKDZ.67171
KasperskyHEUR:Trojan.Win32.Zenpak.pef
RisingTrojan.Kryptik!8.8 (C64:YzY0OggPScA7dWlU)
Ad-AwareTrojan.GenericKDZ.67171
EmsisoftTrojan.GenericKDZ.67171 (B)
ComodoTrojWare.Win32.Spy.Agent.DA@8rxbw1
F-SecureTrojan.TR/AD.Qbot.bfscz
DrWebTrojan.Inject3.40031
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Rimecud.hm
MaxSecureTrojan.Malware.73872809.susgen
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.aaad1bbb21a6fb89
SophosTroj/Qbot-FS
WebrootTrojan.Proxy.Bunitu
AviraTR/AD.Qbot.bfscz
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D10663
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
MicrosoftTrojan:Win32/Qbot.BX!MTB
AhnLab-V3Backdoor/Win32.Qakbot.R336864
Acronissuspicious
VBA32BScope.Trojan.Inject
ALYacTrojan.GenericKDZ.67171
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HDJM
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SMP1
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.HDJM!tr
BitDefenderThetaGen:NN.ZexaF.34122.Jm0@aSzCWyhi
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.5FE6.Malware.Gen

How to remove Trojan.Win32.Zenpak.pef?

Trojan.Win32.Zenpak.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment