Ransom

Ransom:Win32/Enestedel.B!rfn information

Malware Removal

The Ransom:Win32/Enestedel.B!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Enestedel.B!rfn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
srv1100.ru

How to determine Ransom:Win32/Enestedel.B!rfn?


File Info:

crc32: B60887E0
md5: 745c48d2b0aa069d2560ed663bcbc2b9
name: 745C48D2B0AA069D2560ED663BCBC2B9.mlw
sha1: 9ec26acb2b935785790d4f12bf27c47b8387db3f
sha256: 07dd9a67fbfd8e986ff284f8ff011913606b4bfcc3dfa0db7127bca7e073c20a
sha512: 48da60ddad4893b9433b4f0e7d6c7da8e3022025a9b931ed0c9761eccbaf6f1ee3f62cf6cd98bb22bc5bd2901178c3b5e5e649507f15e5ad57b156fa200d7d5e
ssdeep: 3072:kAsj8MBX8s0oXJO2xdk7+/rcfc1OJoT5GQrxLvjlfzddooBa414Wu92P4RlSpI9R:kAsBZXxds+/rcs+Q5plvjlfz/V/4AgRv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Enestedel.B!rfn also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.40491604
FireEyeGeneric.mg.745c48d2b0aa069d
ALYacTrojan.GenericKD.40491604
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cf69f1 )
BitDefenderTrojan.GenericKD.40491604
K7GWTrojan ( 004cf69f1 )
Cybereasonmalicious.2b0aa0
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Trojan.Phorpiex-7581643-1
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Enestedel.490d02fd
NANO-AntivirusTrojan.Win32.Inject.dwvekm
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Agent.Agbk
Ad-AwareTrojan.GenericKD.40491604
EmsisoftTrojan.GenericKD.40491604 (B)
ComodoMalware@#1apnep6d3k1xg
F-SecureHeuristic.HEUR/AGEN.1104967
ZillyaTrojan.Onion.Win32.462
TrendMicroRansom_Enestedel.R002C0DAP21
McAfee-GW-EditionBehavesLike.Win32.Sality.cc
SophosMal/Generic-R + Mal/Cerber-Z
IkarusTrojan.Win32.Injector
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Enestedel
MicrosoftRansom:Win32/Enestedel.B!rfn
ArcabitTrojan.Generic.D269DA54
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.40491604
AhnLab-V3Trojan/Win32.Androm.R271973
Acronissuspicious
McAfeeGeneric.dyn
VBA32TrojanRansom.Enestedel
MalwarebytesMalware.AI.4186448567
PandaTrj/CI.A
ESET-NOD32multiple detections
TrendMicro-HouseCallRansom_Enestedel.R002C0DAP21
RisingRansom.Enestedel!8.E513 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Injector.CIIE!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM42.2.EBED.Malware.Gen

How to remove Ransom:Win32/Enestedel.B!rfn?

Ransom:Win32/Enestedel.B!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment