Trojan

Trojan.Win32.Zenfly.ld removal guide

Malware Removal

The Trojan.Win32.Zenfly.ld is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenfly.ld virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.xmgq68.com
www.bing.com

How to determine Trojan.Win32.Zenfly.ld?


File Info:

crc32: 4474E639
md5: 2cbec8140e278438ca54b16ba714596d
name: gqkd.exe
sha1: 5cefafb2a5bac5e008f09ddbe37427fb459ba481
sha256: 91ac6f5bb77d295458bd10953c39eaa4c1fa74e62236d67914bc443c0c9ab8e4
sha512: a16497374505d19579321b27487df1def0b923a488310821f5d35c61d7f248508fec8ad3063e3f0dc0ebe75d88a1b9bc8ebf3bb1159983dcd3f9ef45b4266a75
ssdeep: 98304:FCCufOOTk2M15tv16ex9KeK6/0tEHtl3HFheIqPjxldnL:FBuffk9x6C5sST3Hajd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x56fax4e54x5de5x4f5cx5ba4
FileVersion: 7.0.0.0
CompanyName: x56fax4e54x5de5x4f5cx5ba4
Comments: x6570x767ex5bb6x5febx9012x6279x91cfx67e5x8be2x5de5x5177
ProductName: x56fax4e54x5febx9012x67e5x8be2x52a9x624b
ProductVersion: 7.0.0.0
FileDescription: x5febx9012x516cx53f8x81eax52a8x8bc6x522bx3001x5febx9012x5355x53f7x6279x91cfx67e5x8be2x8f6fx4ef6
Translation: 0x0804 0x04b0

Trojan.Win32.Zenfly.ld also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.41893209
FireEyeGeneric.mg.2cbec8140e278438
McAfeeArtemis!2CBEC8140E27
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zenfly.4!c
BitDefenderTrojan.GenericKD.41893209
Cybereasonmalicious.40e278
BitDefenderThetaGen:NN.ZexaF.34100.0pKfaqw4O4mb
F-ProtW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.41893209
KasperskyTrojan.Win32.Zenfly.ld
AlibabaTrojan:Win32/Zenfly.6f430318
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:Malware-gen
TencentWin32.Trojan.Zenfly.Huqg
Ad-AwareTrojan.GenericKD.41893209
SophosMal/Generic-S
ComodoPacked.Win32.Cryptcf.A@4pwi81
F-SecureTrojan.TR/Tonmye.wmfdt
ZillyaTrojan.Zenfly.Win32.50
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.GenericKD.41893209 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.CLL.gen!Eldorado
AviraTR/Tonmye.wmfdt
Antiy-AVLTrojan/Win32.Zenfly
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D27F3D59
ZoneAlarmTrojan.Win32.Zenfly.ld
MicrosoftTrojan:Win32/Tonmye.gen!rfn
Acronissuspicious
VBA32BScope.Trojan.Tiggre
ALYacTrojan.GenericKD.41893209
MAXmalware (ai score=99)
MalwarebytesRiskWare.BlackMoon
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
RisingTrojan.Kryptik!1.B3E8 (TFE:5:51PKsw7xEiM)
YandexTrojan.Zenfly!
IkarusVirus.Win32.Heur
eGambitUnsafe.AI_Score_99%
FortinetW32/QQWare.A!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.74556257.susgen

How to remove Trojan.Win32.Zenfly.ld?

Trojan.Win32.Zenfly.ld removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment