Trojan

Trojan.Win32.Zenpak.dotu malicious file

Malware Removal

The Trojan.Win32.Zenpak.dotu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Zenpak.dotu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Zenpak.dotu?


File Info:

name: FD43BA092B07B9702792.mlw
path: /opt/CAPEv2/storage/binaries/225bb2c0876b81b61b361df3ceac39a6b84a532e45c99732f3615666dbb0a719
crc32: 4FA57243
md5: fd43ba092b07b9702792c02ca24e3d94
sha1: 7d16e908d287bdd0ac3814b79dd346793fe1a13b
sha256: 225bb2c0876b81b61b361df3ceac39a6b84a532e45c99732f3615666dbb0a719
sha512: 3238b5f72433a9d22a25161306371dd0fd63373946fd0b41b730dd2135df190a1dded02e8ca4d751f3c456c51a6cb79efd2a3785becbec84e39f379a8436e781
ssdeep: 49152:rLLWnHALv3fYKLMq9TvJQehBnoKrhONJrLeKik:rou3fYKLM2OABoKErrJik
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0A52311B9C48A71D4732C3225595F10A638FC70AF3698EFA3A4D57EDA332C067367A6
sha3_384: bb020ef1aafca071b25054ca35a1494b41380a357137100f96adfe84f498e70e9134af652cc7e8d25644e114504f4432
ep_bytes: e8c6040000e978feffffcccccccccccc
timestamp: 2023-07-20 21:04:33

Version Info:

0: [No Data]

Trojan.Win32.Zenpak.dotu also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zenpak.tsrS
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.69339792
FireEyeGeneric.mg.fd43ba092b07b970
SkyhighBehavesLike.Win32.Generic.tc
ALYacTrojan.GenericKD.69339792
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005948091 )
AlibabaTrojan:Win32/Zenpak.166851de
K7GWTrojan ( 005948091 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Genus.TDS
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Zenpak.dotu
BitDefenderTrojan.GenericKD.69339792
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Zenpak.Etgl
EmsisoftTrojan.GenericKD.69339792 (B)
F-SecureHeuristic.HEUR/AGEN.1364153
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
GDataTrojan.GenericKD.69339792
WebrootW32.Trojan.Uztuby
GoogleDetected
AviraTR/Agent.dmwvs
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Troj.Generic.v
XcitiumMalware@#1zup4j24pih7i
ArcabitTrojan.Generic.D4220A90
ZoneAlarmTrojan.Win32.Zenpak.dotu
MicrosoftTrojan:Win32/Zenpak.C!MTB
VaristW32/Kryptik.KQH.gen!Eldorado
AhnLab-V3Trojan/Win.Zusy.R593370
McAfeeArtemis!FD43BA092B07
VBA32BScope.Trojan.Zenpak
MalwarebytesTrojan.Dropper
PandaTrj/Chgt.AC
RisingTrojan.Zenpak!8.10372 (TFE:1:9M5DzWYSk0U)
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.218514586.susgen
FortinetW32/Kryptik.HUEI!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Zenpak.dotu?

Trojan.Win32.Zenpak.dotu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment