Trojan

Trojan:Win32/Zoxpng.B removal guide

Malware Removal

The Trojan:Win32/Zoxpng.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zoxpng.B virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zoxpng.B?


File Info:

name: 12429B4E1E424355021D.mlw
path: /opt/CAPEv2/storage/binaries/4c42632729b7ec73893be2d7b2372ad02ee7975bf7c534c47227f94d26dc1911
crc32: 35161E95
md5: 12429b4e1e424355021df67d949a0adf
sha1: 8b1a1ec5ebda1c5042576b73fb75b0a575d5b5c9
sha256: 4c42632729b7ec73893be2d7b2372ad02ee7975bf7c534c47227f94d26dc1911
sha512: f1bf114f6c03e0482dad087b875e8be97a5fa1a216bd2e7cc1d8c87104e1c1fdeea8e7d131459e792ca6873220bcc327de3252721a42c67948ceae7296ae84d0
ssdeep: 768:YX2CxlD/LzhNY2WD7l8rKe2pcwu350Zi9zuJN:YXNx17Y2WdTcwuxzub
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2F28D8A955920A7DF0EB8BD0359E2FF6C39439229107EBB4780E4680DD73C6CA7059F
sha3_384: 1336483005aeff7f257d98b35e9541e135f0f751c135bd3752fa84be16ee2f2ec25b419204e19ec3f6bd1292da83a6a7
ep_bytes: 558bec6aff6828314000687023400064
timestamp: 2013-11-14 15:30:30

Version Info:

0: [No Data]

Trojan:Win32/Zoxpng.B also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.12429b4e1e424355
MalwarebytesMalware.AI.3173416650
VIPREGen:Variant.DarkHotel.18
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0055e4041 )
K7AntiVirusTrojan ( 0055e4041 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Small.NJD
APEXMalicious
ClamAVWin.Trojan.Zox-8
KasperskyHEUR:Backdoor.Win32.Winnti.gen
BitDefenderGen:Variant.DarkHotel.18
NANO-AntivirusTrojan.Win32.Edol.dgmpoy
MicroWorld-eScanGen:Variant.DarkHotel.18
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.DarkHotel.18
EmsisoftGen:Variant.DarkHotel.18 (B)
F-SecureHeuristic.HEUR/AGEN.1223803
DrWebBackDoor.Small.103
ZillyaTrojan.Small.Win32.27356
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
JiangminBackdoor.Winnti.gu
AviraHEUR/AGEN.1223803
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Zoxpng.B
ArcabitTrojan.DarkHotel.18
ZoneAlarmHEUR:Backdoor.Win32.Winnti.gen
GDataGen:Variant.DarkHotel.18
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.C599467
ALYacGen:Variant.DarkHotel.18
MAXmalware (ai score=87)
VBA32BScope.Trojan.SvcHorse.01643
CylanceUnsafe
RisingTrojan.Generic@AI.78 (RDMK:cmRtazoIEjwDZAZ6SS9HE0Es0lX5)
YandexTrojan.CryptRedol!T8PsSDhJw4M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaAI:Packer.311F899E1E
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.e1e424
PandaGeneric Malware

How to remove Trojan:Win32/Zoxpng.B?

Trojan:Win32/Zoxpng.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment