Malware

ATK/EncPk-TZ (file analysis)

Malware Removal

The ATK/EncPk-TZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ATK/EncPk-TZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine ATK/EncPk-TZ?


File Info:

crc32: 0A56F02F
md5: 68c5646bcdd0dcf9d1ed67ce6e5a55fc
name: 68C5646BCDD0DCF9D1ED67CE6E5A55FC.mlw
sha1: aaa026a05ef3daf53f239aad5933b9d8bd998030
sha256: 332f8668471629d2c4e251b45b5283a24d47329ad005f5f5c1a9ecc5642839c2
sha512: 2c8200e95a81c90428777da99387d1c86805856ee7cc7b62650545695361a9a5274249588ce371ac3f8fea0a061dd4d589c6ab802812d844e72270e27a145f25
ssdeep: 1536:IPq8rE6I+LA9kzLteNMb+KR0Nc8QsJq39:h8rE6IGqkzqe0Nc8QsC9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009 The Apache Software Foundation.
InternalName: ab.exe
FileVersion: 2.2.14
CompanyName: Apache Software Foundation
Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
FileDescription: ApacheBench command line utility
OriginalFilename: ab.exe
Translation: 0x0409 0x04b0

ATK/EncPk-TZ also known as:

BkavW32.FamVT.RorenNHc.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.CryptZ.Gen
FireEyeGeneric.mg.68c5646bcdd0dcf9
CAT-QuickHealTrojan.Swrort.A
Qihoo-360HEUR/QVM20.1.564F.Malware.Gen
McAfeeSwrort.i
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004c49f81 )
BitDefenderTrojan.CryptZ.Gen
K7GWTrojan ( 004c49f81 )
Cybereasonmalicious.bcdd0d
TrendMicroBKDR_SWRORT.SM
BitDefenderThetaGen:NN.ZexaF.34634.eq1@amGf!9bi
CyrenW32/Swrort.A.gen!Eldorado
SymantecPacked.Generic.347
APEXMalicious
AvastWin32:SwPatch [Wrm]
ClamAVWin.Trojan.MSShellcode-6360730-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Elzob.Gen
Ad-AwareTrojan.CryptZ.Gen
SophosATK/EncPk-TZ
F-SecureTrojan.TR/Patched.Gen2
ZillyaTrojan.Rozena.Win32.106695
InvinceaML/PE-A + ATK/EncPk-TZ
McAfee-GW-EditionBehavesLike.Win32.Swrort.lh
EmsisoftTrojan.CryptZ.Gen (B)
IkarusTrojan.Win32.Swrort
WebrootW32.Malware.Gen
AviraTR/Patched.Gen2
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Meterpreter.O
GridinsoftTrojan.Win32.Swrort.zv!s2
ArcabitTrojan.CryptZ.Gen
SUPERAntiSpywareTrojan.Backdoor-Shell
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.CryptZ.Gen
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Shell.R1283
Acronissuspicious
MalwarebytesTrojan.Rozena
ESET-NOD32a variant of Win32/Rozena.UL
TrendMicro-HouseCallBKDR_SWRORT.SM
RisingHackTool.Swrort!1.6477 (CLASSIC)
YandexTrojan.Rosena.Gen.1
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Generic.AC.C0!tr
AVGWin32:SwPatch [Wrm]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove ATK/EncPk-TZ?

ATK/EncPk-TZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment