Ransom

Ransom:Win32/Enckerbee (file analysis)

Malware Removal

The Ransom:Win32/Enckerbee is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Enckerbee virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup

Related domains:

bookmyroom.pk

How to determine Ransom:Win32/Enckerbee?


File Info:

crc32: 274B7467
md5: 03267acb05bd26405838b8765a3ce675
name: 03267ACB05BD26405838B8765A3CE675.mlw
sha1: 1a3d61dbfd5ddfad79565fb4f1948b0d8bc834dc
sha256: 4b890f5b9677e79743358a5dce325a64d736acf7c1c8a1625fa443dc5f46799f
sha512: 234ef9908344e849af34988b9dc4fbe9dc027d56a40e15dde81a8f78df945cc7a45b50a491517b7f558493f5c22c3b59fc0ef6b7bd1eb6aa42e4e7ef5f4a0cb8
ssdeep: 12288:ZMU0QQ1QJRkpTLY9t9Gw3IESmAHQQlI9sLX:ZMpQX45M9GMIEN1Fo
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Enckerbee also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5666
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.40
CylanceUnsafe
ZillyaBackdoor.Buterat.Win32.2363
SangforRansom.Win32.Enckerbee.mt
AlibabaTrojan:Win32/Enckerbee.12cd1be9
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.b05bd2
ESET-NOD32a variant of Win32/Filecoder.NHJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Scar.rnbx
BitDefenderGen:Heur.Mint.Zard.40
NANO-AntivirusTrojan.Win32.FileCoder.egbtor
MicroWorld-eScanGen:Heur.Mint.Zard.40
TencentWin32.Trojan.Scar.Bxm
Ad-AwareGen:Heur.Mint.Zard.40
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34690.AmGfaib0o7ki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.03267acb05bd2640
EmsisoftGen:Heur.Mint.Zard.40 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Gen.BT
AviraHEUR/AGEN.1122976
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1A2CFE3
MicrosoftRansom:Win32/Enckerbee
ArcabitTrojan.Mint.Zard.40
AegisLabRiskware.Win32.Generic.1!c
ZoneAlarmTrojan.Win32.Scar.rnbx
GDataGen:Heur.Mint.Zard.40
Acronissuspicious
McAfeeArtemis!03267ACB05BD
MAXmalware (ai score=100)
VBA32Backdoor.Buterat
PandaTrj/GdSda.A
RisingRansom.Enckerbee!8.B6C8 (CLOUD)
YandexTrojan.GenAsa!WoG6kJCAEUE
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.NHJ!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Enckerbee?

Ransom:Win32/Enckerbee removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment