Trojan

Trojan:Win32/Zenpak.SM!MSR (file analysis)

Malware Removal

The Trojan:Win32/Zenpak.SM!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zenpak.SM!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Vietnamese
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

tttttt.me
apps.identrust.com
yearofthepig.top

How to determine Trojan:Win32/Zenpak.SM!MSR?


File Info:

crc32: 1530894E
md5: b8d5cdc69c2c1e3a9e3b3c4199afa00f
name: B8D5CDC69C2C1E3A9E3B3C4199AFA00F.mlw
sha1: 92de0169e0cb430203fe326c3f17f8690090588c
sha256: 373ad25892f903a5c92e8f726ebe9a51327421835e2312ebb2d9a705e37c5f10
sha512: 7d9213b51888b2224be9b796ae3bed50d34172dd50a58449f24370e9c75a2ddaac7cd2b14158f2b6a3508cef5c1faa48cafa6b8faf8686bd97a23f092669119d
ssdeep: 12288:IhfCl8VWIdYknFxiTtlKaTkeZ9wHtGVZQrWNV8jP2:gvVWu1inK0fEAC8WP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersions: 7.0.0.15
LegalCopyrights: Wsegda
ProductVersions: 67.0.20.5
Translation: 0x0409 0x08d3

Trojan:Win32/Zenpak.SM!MSR also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72905
FireEyeGeneric.mg.b8d5cdc69c2c1e3a
CAT-QuickHealTrojanpws.Racealer
Qihoo-360Win32/TrojanSpy.Generic.HgIASOsA
ALYacTrojan.GenericKDZ.72905
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Racealer.i!c
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.72905
K7GWTrojan ( 005778471 )
K7AntiVirusTrojan ( 005778471 )
CyrenW32/Kryptik.DGL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Glupteba-9831991-0
KasperskyTrojan-PSW.Win32.Racealer.kps
AlibabaTrojanPSW:Win32/Racealer.fe1d3e17
NANO-AntivirusTrojan.Win32.Racealer.ilntjo
RisingTrojan.Kryptik!1.D251 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.72905
EmsisoftTrojan.GenericKDZ.72905 (B)
ComodoMalware@#ugwhm1tk8j01
F-SecureTrojan.TR/AD.StellarStealer.amqej
TrendMicroTrojanSpy.Win32.GLUPTEBA.USMANB921
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosMal/Generic-S
IkarusTrojan.Win32.Ranumbot
WebrootW32.Trojan.TR.AD.StellarStealer
AviraTR/AD.StellarStealer.amqej
Antiy-AVLTrojan[PSW]/Win32.Racealer
MicrosoftTrojan:Win32/Zenpak.SM!MSR
GridinsoftTrojan.Win32.Kryptik.ns
ArcabitTrojan.Generic.D11CC9
ZoneAlarmTrojan-PSW.Win32.Racealer.kps
GDataTrojan.GenericKDZ.72905
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R365862
Acronissuspicious
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=100)
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HJIO
TrendMicro-HouseCallTrojanSpy.Win32.GLUPTEBA.USMANB921
YandexTrojan.PWS.Racealer!/UxvD4Hqxhw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_77%
FortinetW32/Kryptik.HJJH!tr
BitDefenderThetaGen:NN.ZexaF.34574.FqW@amadlWlG
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.114274561.susgen

How to remove Trojan:Win32/Zenpak.SM!MSR?

Trojan:Win32/Zenpak.SM!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment