Trojan

Should I remove “Trojan:Win32/Zenpak.KAG!MTB”?

Malware Removal

The Trojan:Win32/Zenpak.KAG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zenpak.KAG!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zenpak.KAG!MTB?


File Info:

name: 61364A6FE5EFD106C01A.mlw
path: /opt/CAPEv2/storage/binaries/0a8839b793adedb6f3b7882cd3ff2aca653b29aefe4091969bceffae430b6eaf
crc32: 4B6B85BE
md5: 61364a6fe5efd106c01a7c36ba09abb7
sha1: 90022820444fb45fc831513b51c5f6adaf092307
sha256: 0a8839b793adedb6f3b7882cd3ff2aca653b29aefe4091969bceffae430b6eaf
sha512: 33b82aebe4d1a03f8703d4b4618c2dc7e964eba37701b3ba6acfba8cb20f43eb11c5bbde17cab37e8f364160cee8146102a63609216081cc9b01987cf72e3847
ssdeep: 98304:ystRgLsp8zU/sb5dYLQ5gDxyhQokALsRXzppn:ywgLuz/sb5fyUKJcsN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198E53371BAC2C672E522183F16E09721553CBC300B744EEB5BA46E5E4E246D2963F7B3
sha3_384: 6dbbf76b039d795543e7bde07f7214e1be26eb32ffd7eb5771d879c153ded813e77b50b5e4b38a851ac10620513ff342
ep_bytes: e8dc040000e978feffffe95a45000055
timestamp: 2023-10-03 07:51:24

Version Info:

0: [No Data]

Trojan:Win32/Zenpak.KAG!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34551236
SkyhighBehavesLike.Win32.Generic.wc
McAfeeArtemis!61364A6FE5EF
MalwarebytesTrojan.Dropper.RAR
ZillyaTrojan.Agent.VBS.1874
SangforDownloader.Win32.Fero.Vqbd
K7AntiVirusTrojan ( 005b006a1 )
AlibabaTrojanDownloader:Win32/Zenpak.f2717fab
K7GWTrojan ( 005b006a1 )
BitDefenderThetaGen:NN.ZedlaF.36804.@w8@aOI0ZDdi
VirITTrojan.Win32.Genus.UUP
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DA824
Paloaltogeneric.ml
ClamAVWin.Packed.Filerepmalware-10018152-0
KasperskyTrojan-Downloader.Win32.Fero.gbk
BitDefenderTrojan.Generic.34551236
NANO-AntivirusTrojan.Win32.Fero.kgojvo
AvastWin32:Roshtyak-H [Trj]
TencentWin32.Trojan-Downloader.Fero.Zchl
EmsisoftTrojan.Generic.34551236 (B)
F-SecureHeuristic.HEUR/AGEN.1370540
VIPRETrojan.Generic.34551236
TrendMicroTROJ_GEN.R002C0DA824
FireEyeGeneric.mg.61364a6fe5efd106
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=88)
WebrootW32.Trojan.Uztuby
GoogleDetected
AviraTR/Agent.xneiu
VaristW32/Kryptik.LJN.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Zenpak.KAG!MTB
ArcabitTrojan.Generic.D20F35C4
ZoneAlarmTrojan-Downloader.Win32.Fero.gbk
GDataTrojan.Generic.34551236
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Uztuby.C5570264
VBA32TrojanDownloader.Fero
ALYacTrojan.Generic.34551236
Cylanceunsafe
PandaTrj/Agent.RP
RisingDownloader.Fero!8.18DAE (TFE:2:dzhWwnrDbTG)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.8392565.susgen
FortinetW32/Kryptik.HVWI!tr
AVGWin32:Roshtyak-H [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Fero.gbk

How to remove Trojan:Win32/Zenpak.KAG!MTB?

Trojan:Win32/Zenpak.KAG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment