Malware

Win64/Bazar.AC (file analysis)

Malware Removal

The Win64/Bazar.AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Bazar.AC virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

How to determine Win64/Bazar.AC?


File Info:

crc32: 399EFE4E
md5: 896173f9c5ae0824c38ea6e9be0d6437
name: upload_file
sha1: b9de1e92ae4a5029083a837dcbbebd8e0e5b1097
sha256: 177b312a0c7c2d03be3b2916505fb3e9fdefe785330c74ac29e89cb22656367e
sha512: 48dfafbabc76ee2be3b0d646ee83b42410732f8434940f1ede02d6ed45b9d98c7994b6605eb4a41c4d148cb14436d99407f7a08f0e6175936aae123a38a62105
ssdeep: 49152:/G1dUMJsA2f8ui3OPvBPWJ/H15qfYNJAdk57ZWSBz7FdTiJOSpNXkmO8WlvjM0cb:3kFZ7YNXk58YvjMxmut
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x65e0xff0cx7ffbx7248x4e0dx7a76xff0cx4ec5x4fddx7559x7f72x540dx6743x3002
InternalName: YUVPlayer.exe
FileVersion: 4.0.0.0
CompanyName: x8fdfx601dx5802x5de5x4f5cx5ba4
ProductName: YUVx64adx653ex5668
ProductVersion: 4.0.0.0
FileDescription: YUVPlayer
OriginalFilename: YUVPlayer.exe
Translation: 0x0804 0x04b0

Win64/Bazar.AC also known as:

MicroWorld-eScanTrojan.GenericKD.34793822
FireEyeTrojan.GenericKD.34793822
ALYacTrojan.GenericKD.34793822
AegisLabTrojan.Win32.Zenpak.4!c
K7AntiVirusTrojan ( 005712021 )
BitDefenderTrojan.GenericKD.34793822
K7GWTrojan ( 005712021 )
TrendMicroTROJ_FRS.VSNTJG20
SymantecTrojan.Maltrec.TS
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zenpak.axeq
AlibabaBackdoor:Win64/Bazarldr.307e4271
ViRobotTrojan.Win32.Z.Bazar.2976704
RisingTrojan.Kryptik!8.8 (TFE:5:7RgPTWYhcmG)
Ad-AwareTrojan.GenericKD.34793822
SophosMal/Generic-S
Comodofls.noname@0
F-SecureTrojan.TR/Zenpak.xzjyl
DrWebBackDoor.Bazar.17
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert-S.CU (A)
IkarusTrojan.Win64.Crypt
WebrootW32.Trojan.Bazarloader
AviraTR/Zenpak.xzjyl
MAXmalware (ai score=88)
MicrosoftTrojan:Win64/Bazarldr.G!MSR
ArcabitTrojan.Generic.D212E95E
ZoneAlarmTrojan.Win32.Zenpak.axeq
GDataWin64.Trojan.Kryptik.77BLET
McAfeeArtemis!896173F9C5AE
MalwarebytesTrojan.Bazar
PandaTrj/CI.A
ESET-NOD32Win64/Bazar.AC
TrendMicro-HouseCallTROJ_FRS.VSNTJG20
FortinetW64/Agent.35F2!tr
AVGWin64:CrypterX-gen [Trj]
AvastWin64:CrypterX-gen [Trj]
Qihoo-360Win32/Trojan.8dc

How to remove Win64/Bazar.AC?

Win64/Bazar.AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment