Trojan

What is “Trojan.Win32.Zenpak.cdwp”?

Malware Removal

The Trojan.Win32.Zenpak.cdwp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.cdwp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Zenpak.cdwp?


File Info:

name: 3A6724A9FF03833A2629.mlw
path: /opt/CAPEv2/storage/binaries/f2e6af83f0d1bb085d17a0e594d44796c0d3deff4196677d5f7c297a2ab65e69
crc32: 3253651E
md5: 3a6724a9ff03833a2629bc0c63de5dd1
sha1: 835acc843186002748c5f5bce6ffd175a3858821
sha256: f2e6af83f0d1bb085d17a0e594d44796c0d3deff4196677d5f7c297a2ab65e69
sha512: d51c4407679e119a42fb4fa8d976d02a1751617edf85b1f34f63d851eee92505b81508882704c0437a052c542df21e074f87b7c7f3acb337da17d1c958584955
ssdeep: 49152:/eZBYBfJXAEa6vYZF1MLUEM8TVanxrVLOrZITlJA:/eZBYBfKEaj9MQh8TVmZOcA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3852201BAC180B3D5B30A364F686720DE7EB8704F41CADFE3919D6D99712C15A39BB6
sha3_384: cd1e728cb87d31f64c86c22fc79b89c25fc50beb5dfb4b321aa5a13416fdf53d27e66ab6eb0ed0de50665af92a0c1fed
ep_bytes: e846050000e978feffffcccccccccccc
timestamp: 2022-03-03 11:39:40

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 6.11.1
ProductVersion: 6.11.1
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2022
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Zenpak.cdwp also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Uztuby.4
FireEyeTrojan.Uztuby.4
McAfeeArtemis!3A6724A9FF03
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058f8c81 )
K7GWTrojan ( 0058f8c81 )
CyrenW32/ABRisk.TMFN-5467
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
KasperskyTrojan.Win32.Zenpak.cdwp
BitDefenderTrojan.Uztuby.4
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:InjectorX-gen [Trj]
Ad-AwareTrojan.Uztuby.4
EmsisoftTrojan.Uztuby.4 (B)
VIPRETrojan.Uztuby.4
TrendMicroTROJ_GEN.R023C0RI922
McAfee-GW-EditionArtemis
SophosML/PE-A + Mal/EncPk-APX
GDataGen:Variant.Lazy.241293
GoogleDetected
AviraHEUR/AGEN.1249137
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.813F
ZoneAlarmTrojan.Win32.Zenpak.cdwp
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R482117
BitDefenderThetaGen:NN.ZedlaF.34646.Iv8@aeoO9Oli
ALYacGen:Variant.Lazy.241293
MalwarebytesTrojan.Dropper.SFX
TrendMicro-HouseCallTROJ_GEN.R002H09I722
RisingTrojan.Zenpak!8.10372 (TFE:2:IKo41jgSrrJ)
SentinelOneStatic AI – Malicious SFX
FortinetW32/Kryptik.HQRK!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Zenpak.cdwp?

Trojan.Win32.Zenpak.cdwp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment