Trojan

Trojan:Win32/Zonsterarch.AR malicious file

Malware Removal

The Trojan:Win32/Zonsterarch.AR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zonsterarch.AR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • A possible heap spray exploit has been detected
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan:Win32/Zonsterarch.AR?


File Info:

name: E1C84F49E3909D2FFB3D.mlw
path: /opt/CAPEv2/storage/binaries/b6bd2274d3026969810185ed3be726db80dbc96901ed1522c057b88c5c4e1de8
crc32: E31051B8
md5: e1c84f49e3909d2ffb3d20e0aa6e5189
sha1: 09ade9f8953c41aa7d19e714f270c419d2acc686
sha256: b6bd2274d3026969810185ed3be726db80dbc96901ed1522c057b88c5c4e1de8
sha512: 091bdf56cfe9aaf117d6a4a43d13dd68cf5c3b1f6f7c86f6c93dd881ebe177f533e42730615735698bcd54d2f2ddcf9609b94a4840c6c3c8dce36101baa07ccb
ssdeep: 49152:dHVoIyiHAJ5JAqMbTd/KdfXLYBgHWpACKEk96qRr6:kIytdAfTd/K5XkBJACC6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AD5014EB8A0540AD61CFA3F77A6A121358DA28FAC7C011F7C3F87A6E3170195C59BD6
sha3_384: 69e72cb743c6ca22d922094a730685022b5eec3e32bdcc20f22e8b001978839541ee745a1b5015f23e5e654f5fb36d5b
ep_bytes: 60be006048008dbe00b0f7ffc7872490
timestamp: 2008-10-07 12:03:15

Version Info:

0: [No Data]

Trojan:Win32/Zonsterarch.AR also known as:

tehtrisGeneric.Malware
MicroWorld-eScanApplication.Generic.393791
FireEyeGeneric.mg.e1c84f49e3909d2f
McAfeeArtemis!E1C84F49E390
CylanceUnsafe
VIPREApplication.Generic.393791
SangforTrojan.Win32.Save.a
Cybereasonmalicious.9e3909
CyrenW32/SuspPack.EJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Hoax.ArchSMS.PD
APEXMalicious
ClamAVWin.Adware.Smshoax-33
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.Generic.393791
NANO-AntivirusRiskware.Win32.ArchSMS.crqncp
AvastWin32:PUP-gen [PUP]
TencentWin32.Risk.Hoax.Akey
Ad-AwareApplication.Generic.393791
EmsisoftApplication.Generic.393791 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.SMSSend.2240
ZillyaTool.ArchSMS.Win32.4687
McAfee-GW-EditionBehavesLike.Win32.HLLP.vc
Trapminemalicious.high.ml.score
SophosGeneric PUA AJ (PUA)
IkarusTrojan.Win32.Yakes
GDataApplication.Generic.393791
JiangminTrojan/Generic.wzpl
WebrootW32.Trojan.Archsms
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24D
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Zonsterarch.AR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.ArchSMS.R19963
BitDefenderThetaAI:Packer.E9D8D2EF1E
ALYacApplication.Generic.393791
MAXmalware (ai score=79)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesTrojan.Agent
RisingTrojan.Zonsterarch!8.647 (CLOUD)
YandexTrojan.GenAsa!zxAD/Mm6LOA
SentinelOneStatic AI – Malicious PE
FortinetW32/Yakes.LS!tr
AVGWin32:PUP-gen [PUP]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Zonsterarch.AR?

Trojan:Win32/Zonsterarch.AR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment