Trojan

What is “Trojan.ZenpakPMF.S16487532”?

Malware Removal

The Trojan.ZenpakPMF.S16487532 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ZenpakPMF.S16487532 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.ZenpakPMF.S16487532?


File Info:

crc32: 904C54F7
md5: f8e320bb9822a76131cc8081519193c2
name: F8E320BB9822A76131CC8081519193C2.mlw
sha1: 3bbc944600592a090eead97c08154ca6322ac5dd
sha256: 2eea396a54dc510e970c409a27e501a6651385b75017bf3c903897314630a1b0
sha512: 7148c8997f967c8c6d0f4e189a4121777b01c26f957e5841369c436e071be00bf6a4dace7fe4da66027d5d7f99b27bdfe318fc08cf7f4ad47906c079050040eb
ssdeep: 6144:ubqn/fjsxkXm9gEsHt/J2hUSR3m2OHAt5QI0fGrTTzE:u/xj9g3ZJkUK22vwGrP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.ZenpakPMF.S16487532 also known as:

BkavW32.EmotetGLTHB.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70776
CAT-QuickHealTrojan.ZenpakPMF.S16487532
McAfeeEmotet-FSF!F8E320BB9822
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusTrojan ( 005716471 )
BitDefenderTrojan.GenericKDZ.70776
K7GWTrojan ( 005716471 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTrojan.Win32.MALREP.THKAGBO
CyrenW32/Emotet.AVA.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Dropper.Midie-9779666-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
AlibabaTrojan:Win32/EmotetCrypt.b65edc5d
NANO-AntivirusTrojan.Win32.Zenpak.hzqjfi
ViRobotTrojan.Win32.Z.Emotet.373248.ABQ
RisingTrojan.Emotet!1.CD66 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.70776
EmsisoftTrojan.GenericKDZ.70776 (B)
ComodoMalware@#1rigpyuwi3lnu
F-SecureTrojan.TR/Emotet.xdxhh
DrWebTrojan.DownLoader35.2023
ZillyaTrojan.Emotet.Win32.43768
InvinceaMal/Generic-R + Troj/Emotet-CQY
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.f8e320bb9822a761
SophosTroj/Emotet-CQY
IkarusTrojan-Banker.Agent
JiangminTrojan.Zenpak.dkl
WebrootW32.Trojan.Emotet
AviraTR/Emotet.xdxhh
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Emotet
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/EmotetCrypt.PEF!MTB
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.Generic.D11478
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
GDataTrojan.GenericKDZ.70776
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R353331
BitDefenderThetaGen:NN.ZexaE.34634.wuW@auE!5Xli
ALYacTrojan.Agent.Emotet
TACHYONTrojan/W32.Agent.373248.JB
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CI
TrendMicro-HouseCallTrojan.Win32.MALREP.THKAGBO
TencentMalware.Win32.Gencirc.10ce0a91
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HEOE!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ffa

How to remove Trojan.ZenpakPMF.S16487532?

Trojan.ZenpakPMF.S16487532 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment