Trojan

Trojan:Win32/Zenpak.ASH!MTB removal tips

Malware Removal

The Trojan:Win32/Zenpak.ASH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zenpak.ASH!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zenpak.ASH!MTB?


File Info:

name: 0CA1B0A072A8EDB568D8.mlw
path: /opt/CAPEv2/storage/binaries/1ff9216fabfdd43fb7c6fa695108a25ca580a723237bdccda28fec74f620f176
crc32: 088D2E53
md5: 0ca1b0a072a8edb568d865f3a285a2ee
sha1: 1ed3835b2d8ceaf4449fc21e7176662dd27f6aea
sha256: 1ff9216fabfdd43fb7c6fa695108a25ca580a723237bdccda28fec74f620f176
sha512: 03f228f68909d00134d0bac83ae2f9271ce30ef086d819d5b4533641c82d4288743c328936c4bf2f8420d7df11f1cdb952f2ef3d88989f88f54c4b72b8add4e0
ssdeep: 49152:fIpdKw4vARye/GoiCg3/jYxFRh+jIGzM4Y8wfLWAifB+0dbmZ/UzI5t:gpdYAQeXptxFaMKwjY+0dbk8z
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D2E50109495433CAECFD7C3C554BBBD5C8CC2A295316D82548F5BD8A4AB30FCA2B6627
sha3_384: 757fad3dc9e838f60b3c1912c73b93bda3669c77ed8ff795b9790de87a6a21b6d11ece1db5efba0156c379508dfc9714
ep_bytes: 01d08d05b83d2e10012083ea0a83ea0a
timestamp: 2001-02-22 15:22:22

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Foundation
FileDescription:
FileVersion: 38.7.0
ProductVersion: 38.7.0
InternalName:
LegalTrademarks: Mozilla
OriginalFilename: clearkey.dll
ProductName: Firefox
BuildID: 20160302171452
Translation: 0x0000 0x04b0

Trojan:Win32/Zenpak.ASH!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Emotet.L!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.392195
FireEyeGeneric.mg.0ca1b0a072a8edb5
SkyhighBehavesLike.Win32.Spyware.vc
McAfeeGenericRXWJ-CD!0CA1B0A072A8
ZillyaDownloader.Agent.Win32.549786
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005a9fb81 )
AlibabaTrojanDownloader:Win32/Zenpak.2b524882
K7GWTrojan-Downloader ( 005a9fb81 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36802.!w8@amvNHXli
VirITTrojan.Win32.Genus.TDY
SymantecTrojan.Emotet
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.HCG
TrendMicro-HouseCallTROJ_GEN.R002C0DBH24
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderGen:Variant.Lazy.392195
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Roshtyak-D [Trj]
TencentWin32.Trojan-Downloader.Oader.Anhl
EmsisoftGen:Variant.Lazy.392195 (B)
F-SecureHeuristic.HEUR/AGEN.1364153
VIPREGen:Variant.Lazy.392195
TrendMicroTROJ_GEN.R002C0DBH24
SophosMal/Generic-S
ALYacGen:Variant.Lazy.392195
VaristW32/Kryptik.KQH.gen!Eldorado
AviraHEUR/AGEN.1364153
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.GenKryptik
KingsoftWin32.Trojan.Zenpak.pef
MicrosoftTrojan:Win32/Zenpak.ASH!MTB
ArcabitTrojan.Lazy.D5FC03
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
GDataGen:Variant.Lazy.392195
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R605543
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
GoogleDetected
Cylanceunsafe
PandaTrj/Chgt.AC
RisingTrojan.Zenpak!8.10372 (TFE:1:BEaKfhHFY1L)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.218393777.susgen
FortinetW32/Kryptik.HVWI!tr
AVGWin32:Roshtyak-D [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zenpak.ASH!MTB?

Trojan:Win32/Zenpak.ASH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment