Trojan

What is “Trojan.Win32.Zenpak.dnqm”?

Malware Removal

The Trojan.Win32.Zenpak.dnqm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.dnqm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Zenpak.dnqm?


File Info:

name: AAB613D34245B28182A4.mlw
path: /opt/CAPEv2/storage/binaries/faf12645443a4472221643e8d539aa8a0f9d549ab944f50422b1243452ab0eb5
crc32: DC53224A
md5: aab613d34245b28182a4f1862f05ce7d
sha1: 138fa67dcf8195cdb5f24e19941851ac60e8cf81
sha256: faf12645443a4472221643e8d539aa8a0f9d549ab944f50422b1243452ab0eb5
sha512: 414a7da5d2ff34a4d6541cb419bf5d0591c078c0b1d8e9812c130cf7b3e427f518c28561359895cb5b6cecd1231a2661f8a152d6f971be473e23e8a5f7f7ffa9
ssdeep: 49152:acbz6MUe/CbbAH9y6ZKQ3ZQ6bUq+hQc7t1R3mdibUA2pUGWoF/hqph:acbIbx6xAF75WEVFvYpuh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ECB523637AC1C831D56718352AD59B21FB38FD7017358ACB47885A1E9E316C0AB3A7E3
sha3_384: bb7d5c02ef962115a51e4990fdc0188dcd58ca15cc0dd8cb60503da02c6114f8ea5ae210c54ddeb9c02084cddc2e79f1
ep_bytes: e8dc040000e978feffffe98a46000055
timestamp: 2023-08-01 09:26:15

Version Info:

0: [No Data]

Trojan.Win32.Zenpak.dnqm also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Uztuby.4
ClamAVWin.Packed.Uztuby-10007804-0
McAfeeArtemis!AAB613D34245
VIPRETrojan.Uztuby.4
Cybereasonmalicious.dcf819
BitDefenderThetaGen:NN.ZedlaF.36662.hw8@aa!RJiei
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Zenpak.dnqm
BitDefenderTrojan.Uztuby.4
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastFileRepMalware [Inj]
EmsisoftTrojan.Uztuby.4 (B)
F-SecureTrojan.TR/YAV.Minerva.exsfy
ZillyaTrojan.Zenpak.Win32.19996
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.aab613d34245b281
SophosMal/Dropper-AU
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Uztuby.4
AviraTR/YAV.Minerva.exsfy
MAXmalware (ai score=84)
ArcabitTrojan.Uztuby.4
ZoneAlarmTrojan.Win32.Zenpak.dnqm
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
VBA32Trojan.Zenpak
ALYacTrojan.Uztuby.4
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:0QlUXokKH4zOktBdGZHXPw)
FortinetW32/Kryptik.HUEI!tr
AVGFileRepMalware [Inj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Win32.Zenpak.dnqm?

Trojan.Win32.Zenpak.dnqm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment