Malware

Win32/Injector.ENAL removal instruction

Malware Removal

The Win32/Injector.ENAL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENAL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a JPG image by having ‘jpg’ in the file name.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.ENAL?


File Info:

crc32: 8C261F62
md5: 0fefb456de0c44dbe347c9af0017e49c
name: Me jpg jpgjpg jpg.scr
sha1: ed1ce8ba6a765c7ac221d545efa389afea44cd82
sha256: d2b7389c9dd63fb1b147537c52572bbc09bec5c080474000e113b31aa249388a
sha512: 7d500f3ae5a436cdb5b3cf813da4c578ac6f46ff4f173d0fa48cc8a24951d2386d71b8822b86d63898d3a8209cf8a28874ee7e52fe2132ec0c2d59b81e4b38df
ssdeep: 1536:S9pXDl5+FcrY1Wahm8n7QYGZ8ScEDVXj/AaJ:SLlgFcrY1ZWltAg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Gib9
InternalName: resignation
FileVersion: 1.00
LegalTrademarks: Livsfare9
ProductName: punners
ProductVersion: 1.00
OriginalFilename: resignation.exe

Win32/Injector.ENAL also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34383263
FireEyeTrojan.GenericKD.34383263
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.34383263
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Vebzenpak.4!c
K7AntiVirusTrojan ( 0056cbe31 )
BitDefenderTrojan.GenericKD.34383263
K7GWTrojan ( 0056cbe31 )
Cybereasonmalicious.a6a765
TrendMicroTROJ_GEN.R002C0DHJ20
BitDefenderThetaGen:NN.ZevbaF.34196.fm0@a8Uw1@e
CyrenW32/VBInject.AEG.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.LokiBot-9449868-0
KasperskyTrojan.Win32.Vebzenpak.zgw
ViRobotTrojan.Win32.Z.Malpack.90112.D
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.34383263
SophosMal/Generic-S
ComodoTrojWare.Win32.Unclassified.gen@0
EmsisoftTrojan.GenericKD.34383263 (B)
JiangminTrojan.Vebzenpak.hkk
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Vebzenpak
MicrosoftTrojan:Win32/PonyStealer.VA!MSR
ArcabitTrojan.Generic.D20CA59F
ZoneAlarmTrojan.Win32.Vebzenpak.zgw
GDataTrojan.GenericKD.34383263
McAfeeFareit-FYM!0FEFB456DE0C
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ENAL
TrendMicro-HouseCallTROJ_GEN.R002C0DHJ20
RisingDownloader.Agent!8.B23 (TFE:5:cYnx6fIjW7)
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_92%
FortinetW32/ENAL!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.b2a

How to remove Win32/Injector.ENAL?

Win32/Injector.ENAL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment