Trojan

Trojan.Win32.Zenpak.apyg (file analysis)

Malware Removal

The Trojan.Win32.Zenpak.apyg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.apyg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

How to determine Trojan.Win32.Zenpak.apyg?


File Info:

crc32: 97F32F07
md5: a3f2e592c788a94e18832e09dcb6a101
name: upload_file
sha1: c1ba907c343cf32831b3a7e928392e43036f319f
sha256: 1071d614813b9f2ed318567586294cabe97c545a9c16ec95e83d6b86f529c92c
sha512: fde8180bf3644acc1310a03b1040014c1a84afea16d07e318118556e068ca9e3dd20018e7bd8cfcfa3a07623fcd5e984e7553a37ffb385b9ebd177c6ad780b68
ssdeep: 12288:6UXLmvzeDn+mG+rAJ+jbmYknd73bUdWWqgbZ:6Umen+4rAUmdR4f1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: CHexEditDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CHexEditDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: CHexEditDemo MFC Application
OriginalFilename: CHexEditDemo.EXE
Translation: 0x0409 0x04b0

Trojan.Win32.Zenpak.apyg also known as:

MicroWorld-eScanTrojan.Agent.EUFQ
FireEyeGeneric.mg.a3f2e592c788a94e
McAfeeEmotet-FRI!A3F2E592C788
K7AntiVirusTrojan ( 005600f21 )
BitDefenderTrojan.Agent.EUFQ
K7GWTrojan ( 005600f21 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34144.Pq0@a4ceA9hj
F-ProtW32/Emotet.AOD.gen!Eldorado
SymantecTrojan.Emotet
ESET-NOD32Win32/Emotet.CD
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataTrojan.Agent.EUFQ
KasperskyTrojan.Win32.Zenpak.apyg
AlibabaBackdoor:Win32/Emotet.e9a029d3
Endgamemalicious (high confidence)
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/Kryptik.qddan
DrWebTrojan.DownLoader34.9534
TrendMicroTROJ_GEN.R002C0WGU20
SophosTroj/Emotet-CKJ
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.AOD.gen!Eldorado
AviraTR/Kryptik.qddan
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Emotet.PEE!MTB
ArcabitTrojan.Agent.EUFQ
AhnLab-V3Trojan/Win32.Emotet.R346335
ZoneAlarmTrojan.Win32.Zenpak.apyg
ALYacTrojan.Agent.EUFQ
Ad-AwareTrojan.Agent.EUFQ
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Emotet.C
TrendMicro-HouseCallTROJ_GEN.R002C0WGU20
RisingTrojan.Kryptik!1.C80B (CLOUD)
FortinetW32/Emotet.FHGO!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360Win32/Trojan.5dd

How to remove Trojan.Win32.Zenpak.apyg?

Trojan.Win32.Zenpak.apyg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment