Trojan

How to remove “Trojan.Encpk.Gen.4”?

Malware Removal

The Trojan.Encpk.Gen.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Encpk.Gen.4 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (12 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
smtp.live.com
nichedictionary.com
fastarchofamerica.com
ryumachi-jp.com
bigjohnsbeefjerky.com
nanfangcw.com
debtrescueusa.com
e-shuukyaku.com
woodlandhillwinery.com
violadagamba.com
slcago.org
goodvaluecenter.com
xuanxiao.com
acmepacificrepairs.com
fanxses.com
hinnenwiese.de
theprintinghouseltd.co.uk
nasz-sklep.pl
asj.co.jp
coopsupermarkt.nl
perc.ca
trinity-works.com
marcusgrimes.co.uk
www.hugedomains.com
coop.nl
www.marcusgrimes.co.uk
gcs-cpa.com
www.coop.nl
teasing-video.com
bredainternet.nl
coe.pku.edu.cn
shipeliteexpress.com
survey-smiles.com
www.gcs-cpa.com
ww1.survey-smiles.com
penavision.co.in
appelfarm.org
urantiaproject.com
www.appelfarm.org
lognetic.com
norakuroya.com
plus.ba
shakeyspizza.ph
dbcomponents.com
altonhousehotel.com
www.nanfangcw.com
www.shakeyspizza.ph
sun-ele.co.jp
ajdo.net
trenpalau.com
nazcapictures.com
audience-web.net
westhillsstl.org
xeseofadbavi.kz
currijeipo.kz
huladsaxemi.kz
xiheabulixf.kz
qixsosmog.kz
mattiussiecologia.com
csmbc.org
www.mattiussiecologia.com
nori-k.com
istanbultarim.com.tr
pimlozuvuz.kz
www.istanbultarim.com.tr
toddpipe.com
christybarry.com
biurimex.pl
jeangatz.com
orion-networks.net
redconeretreat.com
sigmametalsinc.com
mail57.us2.mcsv.net
doctsf.com
arquiteturadigital.com
rodeoshow.com.au
graceweb.net
www.doctsf.com
mojacar-vacaciones.com
niray.com.cn
telenavis.com
huzpecjihu.kz
lirurladxeaf.kz
xufukalkisea.kz
rebhimkebp.kz
enzoyrodrigo.com.br
chocolatecovers.com
capitalcitytuxedo.com
joseasawecbe.kz
momonophoto.com
youjoomla.com
al-mawared.com
zeronet.co.jp
ixtractor.com
valuessl.net
simcast.com
fabianonline.de
wumulupumog.kz
vufdoqxeav.kz
geodecisions.com
kabeocoveopo.kz
zoworicanwu.kz
le-mariage.com
www.le-mariage.com
qubufqosbar.kz
d4drmedia.com
ans-service.com
kaufthal.com
genmar.gen.tr
ocsp.digicert.com
crl4.digicert.com
crl3.digicert.com
bapasitaramsevatrust.org
bixfadmiwa.kz
cemowusoqosl.kz
veozeoranpop.kz
walkoqmuz.kz
x.ss2.us
apps.identrust.com
kamaruka.vic.edu.au
golfpark-moossee.ch
espace-hotelier.com
modimalgaca.kz
www.espace-hotelier.com
theautospas.com
justconnect.co.za
www.traderush.com
www.theautospas.com
tvndra.net
areafor.com
re-wakefield.co.uk
zaveifalead.kz
kebjuzadx.kz
xuwidodicosc.kz
cekrijaxu.kz
spiti.org
ginalimo.com
www.spiti.org
wodufusossu.kz
fruitspot.co.za
leadershipforum.us
impex.com.pl
rurqejajo.kz
ladcawalx.kz
beaxufwad.kz
rodageazurja.kz
atr-technologies.com
icigrain.com
pimgumurmi.kz
wsipowerontheweb.com
asterisk.com.sg
steelpennygames.com
4pipp.com
jeigobixd.kz
nadeofekwadz.kz
vixoganubiso.kz
heahopedupo.kz
easygen.com
thedonaldsongroup.com
dohogmogkug.kz
stormwildlifeart.com
jajixwebdimr.kz
xeresanqixke.kz
xufsoscann.kz
rurvugimo.kz
x-cellcommunications.de
naijagurus.com
tollefsondesign.com
berkshirebusiness.org
sdlp.ie
cabooseonline.com
ducejixwuzxu.kz
malagacorp.com
cbsprinting.com.au
floridadoubled.com
tutuji-saitama.com
tavdi.com
schiedel.it
hartmultimedia.com
www.schiedel.com
guveipokoqqu.kz
www.tutuji-saitama.com
deakitzeom.kz
gojunixcanb.kz
peccosqera.kz
boundbydesign.com
buduqdeipeb.kz
rea-soft.ru
courtney.ca
rurpebsek.kz
galfomalqu.kz
cajeadoqqavi.kz
galnoleisi.kz
sgprinting.ca
www.sgprintinginc.com
jarogveolike.kz
nd-evenementiel.com
shs-sales.co.uk
jiwalwalpov.kz
screaminpeach.com
nimcogxin.kz
gurmurxuh.kz
nosvafafil.kz
aethora.com
robertmcintyre.com.au
austriansurfing.at
urayasu.net
www.austriansurfing.at
kehitseokuzc.kz
lewuzfekfix.kz
cewapebfizif.kz
heinixwalqaz.kz
zileigocunix.kz
topex.ro
luhuvadgalce.kz
iktus.fr
kalmeaqeri.kz
www.iktus.fr
bimbeadum.kz
zixepezirox.kz
leizosbixn.kz
brookfarm.com.au
geothermusa.com
paintball.be
xovimnadqeke.kz
gjk.com.pl
veojaveigoqe.kz
fadhakitn.kz
ditkalhaw.kz
xuveigalhige.kz
buzzkillmedia.com
taykon.com
empordalia.com
www.empordalia.com
zolugeivadvu.kz
gamblingonlinemagazine.com
beokijuheidi.kz
mastechn.com
picoboszana.kz
xipevadveibi.kz
xoqenekvigur.kz
photoclubs.com
celebikalip.com.tr
sarahdavid.com
www.photoclubs.com
cksglobal.net
fadgucuva.kz
kvadratoff.ru
theartofhair.com
www.cksglobal.net
www.franckprovost.com.au
gocudeavoqp.kz
poqcixvoq.kz
kebfufnek.kz
kafumihikitx.kz
konishi-hp.com
yamamoto-sr.com
jangeacog.kz
digpro.se
beifosxumiq.kz
digpro.com
ralnaxoxuz.kz
bufufkebmur.kz
nimfufkep.kz
kafrit.com
isrg.trustid.ocsp.identrust.com
kalzokuzli.kz
fujino-lab.com
starmedia.ca
ocsp.comodoca.com
sspackaginggroup.com
wijiseoheoz.kz
beavarogd.kz
padstow.com
zurkitbeid.kz
sullyfrance.com
leinufxedu.kz
authentica-travel.com
sully-immobilier.fr
macgregor.co.kr
business-edge.com
acicinvestor.ca
totalearthcare.com.au
rinixdithimh.kz
fraser-high.school.nz
ocsp.globalsign.com
actfactory.net
lalinixvoxea.kz
audio-direkt.net
e-kagami.com
neurotoxininstitute.com
jitjeixebu.kz
ditzeiluf.kz
kaqanpimfufh.kz
www.e-kagami.com
solutioncorp.com
heliomare.nl
manuyantralaya.com
www.heliomare.nl
rewardhits.com
timeturkey.com
heibawabokal.kz
frederickallergy.com
sztartufi.com
upsilon89.com
lemebjamebj.kz
combine.or.id
arckepesajandek.hu
pobeokudalv.kz
zudalmuzjuvo.kz
moqekjijahab.kz
djkentaro.com
ocsp.int-x3.letsencrypt.org
www.combine.or.id
djkentaro.jp
ocsp.usertrust.com
crl.usertrust.com
nudubeajoze.kz
ocsp.sectigo.com
favuzzurvadp.kz
krafthaus.com
beokexilifuf.kz
miltinio-teatras.lt
deonimqec.kz
qifulanbixnu.kz
ompgp.co.jp
wildrosemarketing.com
www.ompgp.co.jp
ocsp2.globalsign.com
vuzsoglig.kz
crl2.alphassl.com
c21edu.com
lealinadr.kz
fiveosasanv.kz
muzxadjanl.kz
pebcuhuwu.kz
murrebdac.kz

How to determine Trojan.Encpk.Gen.4?


File Info:

crc32: BCAB11C4
md5: 08202600480428f397ca17f0eab78adf
name: 08202600480428F397CA17F0EAB78ADF.mlw
sha1: 33757e9c6f6f6b4a5b051e2f676a6b22039f88ba
sha256: 77830658f94342e31c0da09c017ddf55366fdff8a066de6fe3382d81fc527652
sha512: 9794cc5613c7d3de11114d4fa014a748507dd5657ab18ef9a067ecd6fab6cc047930ba284d50cee42775f35a4011fb49857cc9f50f999b63ad037e91c94faf5d
ssdeep: 1536:bQxRj7kq83J800R6W0yoRmpElkeQy4I9QrduUykU7VvnDFZU+zWGd/OsKSOEfKv2:bMRX/0FJ4frkDFZU+cSBkOSAlZwajZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: bytele
FileVersion: 2.01
CompanyName: loofnbdfe
ProductName: dfgtyhnjhgf
ProductVersion: 2.01
OriginalFilename: bytele.exe

Trojan.Encpk.Gen.4 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.08202600480428f3
CAT-QuickHealWorm.Gamarue.I3
McAfeePWSZbot-FMF!082026004804
CylanceUnsafe
SangforMalware
K7AntiVirusPassword-Stealer ( 0040f69f1 )
K7GWPassword-Stealer ( 0040f69f1 )
CrowdStrikewin/malicious_confidence_100% (D)
InvinceaML/PE-A + Troj/Agent-ADBJ
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderTrojan.Encpk.Gen.4
MicroWorld-eScanTrojan.Encpk.Gen.4
TencentMalware.Win32.Gencirc.10c5bf3f
Ad-AwareTrojan.Encpk.Gen.4
EmsisoftTrojan.Encpk.Gen.4 (B)
ComodoTrojWare.Win32.Injector.AQJJ@54nbeb
F-SecureTrojan:W32/Emotet.B
DrWebTrojan.PWS.Siggen1.10855
VIPRETrojan.Win32.Fareit.sr (v)
TrendMicroTSPY_ZBOT.SMUL
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosTroj/Agent-ADBJ
IkarusTrojan-Spy.Zbot
GDataTrojan.Encpk.Gen.4
JiangminTrojan/PSW.Fareit.cjf
WebrootW32.Rogue.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan[PSW]/Win32.Fareit
GridinsoftMalware.Win32.Pack.37229!se
ArcabitTrojan.Encpk.Gen.4
MicrosoftVirTool:Win32/VBInject.gen!LD
TACHYONTrojan-PWS/W32.VB-Fareit.295055
AhnLab-V3Spyware/Win32.RL_Zbot.R355710
BitDefenderThetaGen:NN.ZevbaF.34634.im3@ay3p5uji
ALYacTrojan.Encpk.Gen.4
MAXmalware (ai score=88)
VBA32TrojanPSW.Fareit
MalwarebytesTrojan.Downloader
ZonerTrojan.Win32.20075
ESET-NOD32a variant of Win32/Injector.ARJI
TrendMicro-HouseCallTSPY_ZBOT.SMUL
RisingTrojan.DL.Win32.Wauchos.cc (CLASSIC)
YandexTrojan.GenAsa!sTWABK0A5Wc
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.ATCM!tr
AVGWin32:Downloader-UPK [Trj]
Cybereasonmalicious.048042
PandaTrj/Genetic.gen
Qihoo-360HEUR/QVM18.1.564F.Malware.Gen

How to remove Trojan.Encpk.Gen.4?

Trojan.Encpk.Gen.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment