Categories: Trojan

How to remove “Trojan.Encpk.Gen.4”?

The Trojan.Encpk.Gen.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Encpk.Gen.4 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (12 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
smtp.live.com
nichedictionary.com
fastarchofamerica.com
ryumachi-jp.com
bigjohnsbeefjerky.com
nanfangcw.com
debtrescueusa.com
e-shuukyaku.com
woodlandhillwinery.com
violadagamba.com
slcago.org
goodvaluecenter.com
xuanxiao.com
acmepacificrepairs.com
fanxses.com
hinnenwiese.de
theprintinghouseltd.co.uk
nasz-sklep.pl
asj.co.jp
coopsupermarkt.nl
perc.ca
trinity-works.com
marcusgrimes.co.uk
www.hugedomains.com
coop.nl
www.marcusgrimes.co.uk
gcs-cpa.com
www.coop.nl
teasing-video.com
bredainternet.nl
coe.pku.edu.cn
shipeliteexpress.com
survey-smiles.com
www.gcs-cpa.com
ww1.survey-smiles.com
penavision.co.in
appelfarm.org
urantiaproject.com
www.appelfarm.org
lognetic.com
norakuroya.com
plus.ba
shakeyspizza.ph
dbcomponents.com
altonhousehotel.com
www.nanfangcw.com
www.shakeyspizza.ph
sun-ele.co.jp
ajdo.net
trenpalau.com
nazcapictures.com
audience-web.net
westhillsstl.org
xeseofadbavi.kz
currijeipo.kz
huladsaxemi.kz
xiheabulixf.kz
qixsosmog.kz
mattiussiecologia.com
csmbc.org
www.mattiussiecologia.com
nori-k.com
istanbultarim.com.tr
pimlozuvuz.kz
www.istanbultarim.com.tr
toddpipe.com
christybarry.com
biurimex.pl
jeangatz.com
orion-networks.net
redconeretreat.com
sigmametalsinc.com
mail57.us2.mcsv.net
doctsf.com
arquiteturadigital.com
rodeoshow.com.au
graceweb.net
www.doctsf.com
mojacar-vacaciones.com
niray.com.cn
telenavis.com
huzpecjihu.kz
lirurladxeaf.kz
xufukalkisea.kz
rebhimkebp.kz
enzoyrodrigo.com.br
chocolatecovers.com
capitalcitytuxedo.com
joseasawecbe.kz
momonophoto.com
youjoomla.com
al-mawared.com
zeronet.co.jp
ixtractor.com
valuessl.net
simcast.com
fabianonline.de
wumulupumog.kz
vufdoqxeav.kz
geodecisions.com
kabeocoveopo.kz
zoworicanwu.kz
le-mariage.com
www.le-mariage.com
qubufqosbar.kz
d4drmedia.com
ans-service.com
kaufthal.com
genmar.gen.tr
ocsp.digicert.com
crl4.digicert.com
crl3.digicert.com
bapasitaramsevatrust.org
bixfadmiwa.kz
cemowusoqosl.kz
veozeoranpop.kz
walkoqmuz.kz
x.ss2.us
apps.identrust.com
kamaruka.vic.edu.au
golfpark-moossee.ch
espace-hotelier.com
modimalgaca.kz
www.espace-hotelier.com
theautospas.com
justconnect.co.za
www.traderush.com
www.theautospas.com
tvndra.net
areafor.com
re-wakefield.co.uk
zaveifalead.kz
kebjuzadx.kz
xuwidodicosc.kz
cekrijaxu.kz
spiti.org
ginalimo.com
www.spiti.org
wodufusossu.kz
fruitspot.co.za
leadershipforum.us
impex.com.pl
rurqejajo.kz
ladcawalx.kz
beaxufwad.kz
rodageazurja.kz
atr-technologies.com
icigrain.com
pimgumurmi.kz
wsipowerontheweb.com
asterisk.com.sg
steelpennygames.com
4pipp.com
jeigobixd.kz
nadeofekwadz.kz
vixoganubiso.kz
heahopedupo.kz
easygen.com
thedonaldsongroup.com
dohogmogkug.kz
stormwildlifeart.com
jajixwebdimr.kz
xeresanqixke.kz
xufsoscann.kz
rurvugimo.kz
x-cellcommunications.de
naijagurus.com
tollefsondesign.com
berkshirebusiness.org
sdlp.ie
cabooseonline.com
ducejixwuzxu.kz
malagacorp.com
cbsprinting.com.au
floridadoubled.com
tutuji-saitama.com
tavdi.com
schiedel.it
hartmultimedia.com
www.schiedel.com
guveipokoqqu.kz
www.tutuji-saitama.com
deakitzeom.kz
gojunixcanb.kz
peccosqera.kz
boundbydesign.com
buduqdeipeb.kz
rea-soft.ru
courtney.ca
rurpebsek.kz
galfomalqu.kz
cajeadoqqavi.kz
galnoleisi.kz
sgprinting.ca
www.sgprintinginc.com
jarogveolike.kz
nd-evenementiel.com
shs-sales.co.uk
jiwalwalpov.kz
screaminpeach.com
nimcogxin.kz
gurmurxuh.kz
nosvafafil.kz
aethora.com
robertmcintyre.com.au
austriansurfing.at
urayasu.net
www.austriansurfing.at
kehitseokuzc.kz
lewuzfekfix.kz
cewapebfizif.kz
heinixwalqaz.kz
zileigocunix.kz
topex.ro
luhuvadgalce.kz
iktus.fr
kalmeaqeri.kz
www.iktus.fr
bimbeadum.kz
zixepezirox.kz
leizosbixn.kz
brookfarm.com.au
geothermusa.com
paintball.be
xovimnadqeke.kz
gjk.com.pl
veojaveigoqe.kz
fadhakitn.kz
ditkalhaw.kz
xuveigalhige.kz
buzzkillmedia.com
taykon.com
empordalia.com
www.empordalia.com
zolugeivadvu.kz
gamblingonlinemagazine.com
beokijuheidi.kz
mastechn.com
picoboszana.kz
xipevadveibi.kz
xoqenekvigur.kz
photoclubs.com
celebikalip.com.tr
sarahdavid.com
www.photoclubs.com
cksglobal.net
fadgucuva.kz
kvadratoff.ru
theartofhair.com
www.cksglobal.net
www.franckprovost.com.au
gocudeavoqp.kz
poqcixvoq.kz
kebfufnek.kz
kafumihikitx.kz
konishi-hp.com
yamamoto-sr.com
jangeacog.kz
digpro.se
beifosxumiq.kz
digpro.com
ralnaxoxuz.kz
bufufkebmur.kz
nimfufkep.kz
kafrit.com
isrg.trustid.ocsp.identrust.com
kalzokuzli.kz
fujino-lab.com
starmedia.ca
ocsp.comodoca.com
sspackaginggroup.com
wijiseoheoz.kz
beavarogd.kz
padstow.com
zurkitbeid.kz
sullyfrance.com
leinufxedu.kz
authentica-travel.com
sully-immobilier.fr
macgregor.co.kr
business-edge.com
acicinvestor.ca
totalearthcare.com.au
rinixdithimh.kz
fraser-high.school.nz
ocsp.globalsign.com
actfactory.net
lalinixvoxea.kz
audio-direkt.net
e-kagami.com
neurotoxininstitute.com
jitjeixebu.kz
ditzeiluf.kz
kaqanpimfufh.kz
www.e-kagami.com
solutioncorp.com
heliomare.nl
manuyantralaya.com
www.heliomare.nl
rewardhits.com
timeturkey.com
heibawabokal.kz
frederickallergy.com
sztartufi.com
upsilon89.com
lemebjamebj.kz
combine.or.id
arckepesajandek.hu
pobeokudalv.kz
zudalmuzjuvo.kz
moqekjijahab.kz
djkentaro.com
ocsp.int-x3.letsencrypt.org
www.combine.or.id
djkentaro.jp
ocsp.usertrust.com
crl.usertrust.com
nudubeajoze.kz
ocsp.sectigo.com
favuzzurvadp.kz
krafthaus.com
beokexilifuf.kz
miltinio-teatras.lt
deonimqec.kz
qifulanbixnu.kz
ompgp.co.jp
wildrosemarketing.com
www.ompgp.co.jp
ocsp2.globalsign.com
vuzsoglig.kz
crl2.alphassl.com
c21edu.com
lealinadr.kz
fiveosasanv.kz
muzxadjanl.kz
pebcuhuwu.kz
murrebdac.kz

How to determine Trojan.Encpk.Gen.4?


File Info:

crc32: BCAB11C4md5: 08202600480428f397ca17f0eab78adfname: 08202600480428F397CA17F0EAB78ADF.mlwsha1: 33757e9c6f6f6b4a5b051e2f676a6b22039f88basha256: 77830658f94342e31c0da09c017ddf55366fdff8a066de6fe3382d81fc527652sha512: 9794cc5613c7d3de11114d4fa014a748507dd5657ab18ef9a067ecd6fab6cc047930ba284d50cee42775f35a4011fb49857cc9f50f999b63ad037e91c94faf5dssdeep: 1536:bQxRj7kq83J800R6W0yoRmpElkeQy4I9QrduUykU7VvnDFZU+zWGd/OsKSOEfKv2:bMRX/0FJ4frkDFZU+cSBkOSAlZwajZtype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0InternalName: byteleFileVersion: 2.01CompanyName: loofnbdfeProductName: dfgtyhnjhgfProductVersion: 2.01OriginalFilename: bytele.exe

Trojan.Encpk.Gen.4 also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.08202600480428f3
CAT-QuickHeal Worm.Gamarue.I3
McAfee PWSZbot-FMF!082026004804
Cylance Unsafe
Sangfor Malware
K7AntiVirus Password-Stealer ( 0040f69f1 )
K7GW Password-Stealer ( 0040f69f1 )
CrowdStrike win/malicious_confidence_100% (D)
Invincea ML/PE-A + Troj/Agent-ADBJ
Symantec ML.Attribute.HighConfidence
APEX Malicious
BitDefender Trojan.Encpk.Gen.4
MicroWorld-eScan Trojan.Encpk.Gen.4
Tencent Malware.Win32.Gencirc.10c5bf3f
Ad-Aware Trojan.Encpk.Gen.4
Emsisoft Trojan.Encpk.Gen.4 (B)
Comodo TrojWare.Win32.Injector.AQJJ@54nbeb
F-Secure Trojan:W32/Emotet.B
DrWeb Trojan.PWS.Siggen1.10855
VIPRE Trojan.Win32.Fareit.sr (v)
TrendMicro TSPY_ZBOT.SMUL
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
Sophos Troj/Agent-ADBJ
Ikarus Trojan-Spy.Zbot
GData Trojan.Encpk.Gen.4
Jiangmin Trojan/PSW.Fareit.cjf
Webroot W32.Rogue.Gen
Avira TR/Crypt.ULPM.Gen
Antiy-AVL Trojan[PSW]/Win32.Fareit
Gridinsoft Malware.Win32.Pack.37229!se
Arcabit Trojan.Encpk.Gen.4
Microsoft VirTool:Win32/VBInject.gen!LD
TACHYON Trojan-PWS/W32.VB-Fareit.295055
AhnLab-V3 Spyware/Win32.RL_Zbot.R355710
BitDefenderTheta Gen:NN.ZevbaF.34634.im3@ay3p5uji
ALYac Trojan.Encpk.Gen.4
MAX malware (ai score=88)
VBA32 TrojanPSW.Fareit
Malwarebytes Trojan.Downloader
Zoner Trojan.Win32.20075
ESET-NOD32 a variant of Win32/Injector.ARJI
TrendMicro-HouseCall TSPY_ZBOT.SMUL
Rising Trojan.DL.Win32.Wauchos.cc (CLASSIC)
Yandex Trojan.GenAsa!sTWABK0A5Wc
SentinelOne Static AI – Malicious PE
Fortinet W32/Injector.ATCM!tr
AVG Win32:Downloader-UPK [Trj]
Cybereason malicious.048042
Panda Trj/Genetic.gen
Qihoo-360 HEUR/QVM18.1.564F.Malware.Gen

How to remove Trojan.Encpk.Gen.4?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry
Tags: 4pipp.coma.tomx.xyzacicinvestor.caacmepacificrepairs.comactfactory.netaethora.comajdo.netal-mawared.comaltonhousehotel.comans-service.comappelfarm.orgapps.identrust.comarckepesajandek.huareafor.comarquiteturadigital.comasj.co.jpasterisk.com.sgatr-technologies.comaudience-web.netaudio-direkt.netaustriansurfing.atauthentica-travel.combapasitaramsevatrust.orgbeavarogd.kzbeaxufwad.kzbeifosxumiq.kzbeokexilifuf.kzbeokijuheidi.kzberkshirebusiness.orgbigjohnsbeefjerky.combimbeadum.kzbiurimex.plbixfadmiwa.kzboundbydesign.combredainternet.nlbrookfarm.com.aubuduqdeipeb.kzbufufkebmur.kzbusiness-edge.combuzzkillmedia.combytelec21edu.comcabooseonline.comcajeadoqqavi.kzcapitalcitytuxedo.comcbsprinting.com.aucekrijaxu.kzcelebikalip.com.trcemowusoqosl.kzcewapebfizif.kzchocolatecovers.comchristybarry.comcksglobal.netcoe.pku.edu.cncombine.or.idcoop.nlcoopsupermarkt.nlcourtney.cacrl.usertrust.comcrl2.alphassl.comcrl3.digicert.comcrl4.digicert.comcsmbc.orgcurrijeipo.kzd4drmedia.comdbcomponents.comdeakitzeom.kzdebtrescueusa.comdeonimqec.kzdigpro.comdigpro.seditkalhaw.kzditzeiluf.kzdjkentaro.comdjkentaro.jpdoctsf.comdohogmogkug.kzducejixwuzxu.kze-kagami.come-shuukyaku.comeasygen.comempordalia.comenzoyrodrigo.com.brespace-hotelier.comfabianonline.defadgucuva.kzfadhakitn.kzfanxses.comfastarchofamerica.comfavuzzurvadp.kzfiveosasanv.kzfloridadoubled.comfraser-high.school.nzfrederickallergy.comfruitspot.co.zafujino-lab.comgalfomalqu.kzgalnoleisi.kzgamblingonlinemagazine.comgcs-cpa.comgenmar.gen.trgeodecisions.comgeothermusa.comginalimo.comgjk.com.plgocudeavoqp.kzgojunixcanb.kzgolfpark-moossee.chgoodvaluecenter.comgraceweb.netgurmurxuh.kzguveipokoqqu.kzhartmultimedia.comheahopedupo.kzheibawabokal.kzheinixwalqaz.kzheliomare.nlhinnenwiese.dehuladsaxemi.kzhuzpecjihu.kzicigrain.comiktus.frimpex.com.plisrg.trustid.ocsp.identrust.comistanbultarim.com.trixtractor.comjajixwebdimr.kzjangeacog.kzjarogveolike.kzjeangatz.comjeigobixd.kzjitjeixebu.kzjiwalwalpov.kzjoseasawecbe.kzjustconnect.co.zakabeocoveopo.kzkafrit.comkafumihikitx.kzkalmeaqeri.kzkalzokuzli.kzkamaruka.vic.edu.aukaqanpimfufh.kzkaufthal.comkebfufnek.kzkebjuzadx.kzkehitseokuzc.kzkonishi-hp.comkrafthaus.comkvadratoff.ruladcawalx.kzlalinixvoxea.kzle-mariage.comleadershipforum.uslealinadr.kzleinufxedu.kzleizosbixn.kzlemebjamebj.kzlewuzfekfix.kzlirurladxeaf.kzlognetic.comluhuvadgalce.kzmacgregor.co.krmail57.us2.mcsv.netmalagacorp.commanuyantralaya.commarcusgrimes.co.ukmastechn.commattiussiecologia.commiltinio-teatras.ltmodimalgaca.kzmojacar-vacaciones.commomonophoto.commoqekjijahab.kzmurrebdac.kzmuzxadjanl.kznadeofekwadz.kznaijagurus.comnanfangcw.comnasz-sklep.plnazcapictures.comnd-evenementiel.comneurotoxininstitute.comnichedictionary.comnimcogxin.kznimfufkep.kzniray.com.cnnorakuroya.comnori-k.comnosvafafil.kznudubeajoze.kzocsp.comodoca.comocsp.digicert.comocsp.globalsign.comocsp.int-x3.letsencrypt.orgocsp.sectigo.comocsp.usertrust.comocsp2.globalsign.comompgp.co.jporion-networks.netpadstow.compaintball.bepebcuhuwu.kzpeccosqera.kzpenavision.co.inperc.caphotoclubs.compicoboszana.kzpimgumurmi.kzpimlozuvuz.kzplus.bapobeokudalv.kzpoqcixvoq.kzqifulanbixnu.kzqixsosmog.kzqubufqosbar.kzralnaxoxuz.kzre-wakefield.co.ukrea-soft.rurebhimkebp.kzredconeretreat.comrewardhits.comrinixdithimh.kzrobertmcintyre.com.aurodageazurja.kzrodeoshow.com.aururpebsek.kzrurqejajo.kzrurvugimo.kzryumachi-jp.comsarahdavid.comschiedel.itscreaminpeach.comsdlp.iesgprinting.cashakeyspizza.phshipeliteexpress.comshs-sales.co.uksigmametalsinc.comsimcast.comslcago.orgsmtp.live.comsolutioncorp.comspiti.orgsspackaginggroup.comstarmedia.casteelpennygames.comstormwildlifeart.comsully-immobilier.frsullyfrance.comsun-ele.co.jpsurvey-smiles.comsztartufi.comtavdi.comtaykon.comteasing-video.comtelenavis.comtheartofhair.comtheautospas.comthedonaldsongroup.comtheprintinghouseltd.co.uktimeturkey.comtoddpipe.comtollefsondesign.comtopex.rototalearthcare.com.autrenpalau.comtrinity-works.comTrojan.Encpk.Gen.4tutuji-saitama.comtvndra.netupsilon89.comurantiaproject.comurayasu.netvaluessl.netveojaveigoqe.kzveozeoranpop.kzvioladagamba.comvixoganubiso.kzvufdoqxeav.kzvuzsoglig.kzwalkoqmuz.kzwesthillsstl.orgwijiseoheoz.kzwildrosemarketing.comwodufusossu.kzwoodlandhillwinery.comwsipowerontheweb.comwumulupumog.kzww1.survey-smiles.comwww.appelfarm.orgwww.austriansurfing.atwww.cksglobal.netwww.combine.or.idwww.coop.nlwww.doctsf.comwww.e-kagami.comwww.empordalia.comwww.espace-hotelier.comwww.franckprovost.com.auwww.gcs-cpa.comwww.heliomare.nlwww.hugedomains.comwww.iktus.frwww.istanbultarim.com.trwww.le-mariage.comwww.marcusgrimes.co.ukwww.mattiussiecologia.comwww.nanfangcw.comwww.ompgp.co.jpwww.photoclubs.comwww.schiedel.comwww.sgprintinginc.comwww.shakeyspizza.phwww.spiti.orgwww.theautospas.comwww.traderush.comwww.tutuji-saitama.comx-cellcommunications.dex.ss2.usxeresanqixke.kzxeseofadbavi.kzxiheabulixf.kzxipevadveibi.kzxoqenekvigur.kzxovimnadqeke.kzxuanxiao.comxufsoscann.kzxufukalkisea.kzxuveigalhige.kzxuwidodicosc.kzyamamoto-sr.comyoujoomla.comz.whorecord.xyzzaveifalead.kzzeronet.co.jpzileigocunix.kzzixepezirox.kzzolugeivadvu.kzzoworicanwu.kzzudalmuzjuvo.kzzurkitbeid.kz

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

6 hours ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

6 hours ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

6 hours ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

6 hours ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

6 hours ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

6 hours ago