Trojan

Should I remove “Trojan.Win32.Zenpak.cdeh”?

Malware Removal

The Trojan.Win32.Zenpak.cdeh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.cdeh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Zenpak.cdeh?


File Info:

name: 0D6439F8A39535F804CA.mlw
path: /opt/CAPEv2/storage/binaries/b5b2c55833fa4eb7e7b842bb2c9c0deb17b6c836eebea2e0c95497aedde9338b
crc32: C88E6CDD
md5: 0d6439f8a39535f804ca510f623ddb4d
sha1: 7321f3498a4dd6a5f12064baec11121b6cc5623d
sha256: b5b2c55833fa4eb7e7b842bb2c9c0deb17b6c836eebea2e0c95497aedde9338b
sha512: 4c46e4afb093637ab976fb2514d26b4b9d58c66b87a2dff54b9d98670c250d9eb67edde256ed5adbcd040d179314b25f1a0e0fbe6d861e7132eaf44b2b48007c
ssdeep: 49152:EuWx6M+phwhdijTlb1ioAymUu0U34wju3u6yZTBOg:EuWqh+dGpZi/jljuIZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185952342FBC154B2D57A2E3349154E21A83DBC362B79CEDF6398151DEA302D0CA3A767
sha3_384: af71418b9770be72eda3905a5353e792f6f7b40f7f50817115451082178c1fa551d14f59bf2b419845d8b38ae77308d2
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-01-24 07:31:18

Version Info:

0: [No Data]

Trojan.Win32.Zenpak.cdeh also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Uztuby.4
FireEyeGeneric.mg.0d6439f8a39535f8
McAfeeArtemis!0D6439F8A395
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005932001 )
BitDefenderTrojan.Uztuby.4
K7GWTrojan ( 005932001 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Uztuby.4
CyrenW32/S-1b09bef6!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Zenpak.cdeh
NANO-AntivirusTrojan.Win32.Zenpak.jsbrnu
RisingTrojan.Zenpak!8.10372 (TFE:1:IdKOm6xU2D)
Ad-AwareTrojan.Uztuby.4
EmsisoftTrojan.Uztuby.4 (B)
VIPRETrojan.Uztuby.4
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious SFX
AviraTR/Agent.mgojp
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Lazy.240364
GoogleDetected
Acronissuspicious
VBA32BScope.Trojan.Zenpak
MaxSecureTrojan.Malware.121218.susgen
FortinetPossibleThreat.PALLASNET.H
BitDefenderThetaGen:NN.ZedlaF.34646.Pz8@amdaDpai
AVGWin32:InjectorX-gen [Trj]
Cybereasonmalicious.98a4dd
AvastWin32:InjectorX-gen [Trj]

How to remove Trojan.Win32.Zenpak.cdeh?

Trojan.Win32.Zenpak.cdeh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment