Malware

Mal/EncPk-BQ (file analysis)

Malware Removal

The Mal/EncPk-BQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/EncPk-BQ virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/EncPk-BQ?


File Info:

name: D1A7237C7695E774E6E9.mlw
path: /opt/CAPEv2/storage/binaries/bee01eb99dcaeeb6fd26fadc3ca6d904c1b3e6d5c2d3e5c240e70dab58ea754f
crc32: E54E3ABD
md5: d1a7237c7695e774e6e9247749e58405
sha1: b7533be682c152678906908e6b4fbb4d1ebd2fa2
sha256: bee01eb99dcaeeb6fd26fadc3ca6d904c1b3e6d5c2d3e5c240e70dab58ea754f
sha512: a0190655962098a43be7957e3d1ab6a188639011b77e909aa2f95c39fa8b58a37793458d1469011cab2eadfecae942630e2344bb7a7231865bd06d021a62ae46
ssdeep: 24576:2GYvGsUH8spk563jwEKJaj9MTo5BUw1eX+xLD4ePQrSX:Q+sI8q3jZU49MTmz1DRYrSX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D66512A5BB988530F2C5AA335097CED58DA88638D24D2D1A4153062ECCFE2D7BC5F47E
sha3_384: dbab7cc2b1b0113608ae07706831772bb577aeb0d2215fc744004ed1d193a2d39928f4f18903e146942f65510e9d2ef8
ep_bytes: b85d5760f08d889e1200108941018b54
timestamp: 2009-05-06 02:21:07

Version Info:

FileDescription: Uninstall Visualizador 6.1.8
OriginalFilename: uninstall.exe
:
Translation: 0x0409 0x04b0

Mal/EncPk-BQ also known as:

LionicTrojan.Win32.Agent.lrr0
MicroWorld-eScanTrojan.GenericKD.36237025
FireEyeTrojan.GenericKD.36237025
McAfeeArtemis!D1A7237C7695
MalwarebytesMalware.Heuristic.1003
ZillyaTrojan.Kryptik.Win32.1218641
SangforTrojan.Win32.Skeeyah.A
K7AntiVirusTrojan ( 0020f4671 )
AlibabaTrojan:Win32/Kryptik.6c89cd0c
K7GWTrojan ( 0020f4671 )
Cybereasonmalicious.c7695e
CyrenW32/SuspPack.DO.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.TG
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.36237025
AvastWin32:Evo-gen [Trj]
TencentPacked.Win32.Crashcompact.a
EmsisoftTrojan.GenericKD.36237025 (B)
F-SecureTrojan.TR/Crypt.PEPM.Gen
VIPRETrojan.GenericKD.36237025
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
SophosMal/EncPk-BQ
GDataTrojan.GenericKD.36237025
JiangminPacked.Multi.dvo
GoogleDetected
AviraTR/Crypt.PEPM.Gen
Antiy-AVLTrojan/Win32.SGeneric
XcitiumTrojWare.Win32.Kryptik.~NTG@1pel9l
ArcabitTrojan.Generic.D228EEE1
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.R287565
BitDefenderThetaGen:NN.ZexaF.36196.Dj3faeDO2nhi
ALYacTrojan.GenericKD.36237025
Cylanceunsafe
RisingTrojan.Tiggre!8.ED98 (CLOUD)
YandexTrojan.Kryptik!JNZ13IB3Glk
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.TG!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Mal/EncPk-BQ?

Mal/EncPk-BQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment