Trojan

Trojan.Agent.ENRW malicious file

Malware Removal

The Trojan.Agent.ENRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.ENRW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Japanese
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Agent.ENRW?


File Info:

crc32: 5C402550
md5: 4ed631870edef4cea521abc02f133ee5
name: 4ED631870EDEF4CEA521ABC02F133EE5.mlw
sha1: 457924f554df9ebb14316479f01545433bb8c7f4
sha256: ce6beddc1a34ca1835e2f044cb9283fdb7ab4dad2e75afe4fda230feb462db0a
sha512: 144baf97e184ccd3ad2711f4879ca21a98884f4e5bcc0433992620cf96ff7dcd10131d7f2b838c9ba7d0b0313f4c9dd4265bd33647a6b2aa2ce4cfe065beb931
ssdeep: 6144:6Qhw59G7KuSKizfyhixW45DmbQDGJQvxmB:6aw5U7/SKiz68BmbQiJQ
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Agent.ENRW also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005623861 )
LionicTrojan.Win32.Agentb.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.28004
CynetMalicious (score: 100)
ALYacTrojan.Agent.ENRW
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1966878
SangforTrojan.Win64.Beerish.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Azorult.183b4acf
K7GWTrojan ( 005623861 )
Cybereasonmalicious.70edef
SymantecRansom.Nemty
ESET-NOD32a variant of Win32/Kryptik.HBVR
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Agentb.jxfi
BitDefenderTrojan.Agent.ENRW
NANO-AntivirusTrojan.Win32.Encoder.hfjqgd
ViRobotTrojan.Win32.Z.Kryptik.229376.XI
MicroWorld-eScanTrojan.Agent.ENRW
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.Agent.ENRW
SophosMal/Generic-R + Mal/RyPack-A
BitDefenderThetaGen:NN.ZexaF.34236.omGfaKG8hokG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DK121
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.4ed631870edef4ce
EmsisoftTrojan.Agent.ENRW (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Sodin.m
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3019B0F
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Azorult.VSD!MTB
ArcabitTrojan.Agent.ENRW
SUPERAntiSpywareRansom.GandCrab/Variant
GDataTrojan.Agent.ENRW
AhnLab-V3Trojan/Win32.Yakes.C1659774
McAfeeArtemis!4ED631870EDE
MAXmalware (ai score=85)
VBA32BScope.Trojan.AET.281105
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.C45C (CLASSIC)
YandexTrojan.GenAsa!iAUgt80CTK4
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HBSU!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Agent.ENRW?

Trojan.Agent.ENRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment