Malware

Should I remove “Win32/Injector.ENKS”?

Malware Removal

The Win32/Injector.ENKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENKS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Win32/Injector.ENKS?


File Info:

crc32: 541E90F5
md5: dd6076dc3359bb7fc8af5798bc597052
name: upload_file
sha1: 6a0e446b7d6e6662402d6b3e04277e260f17d711
sha256: 54ece456535973a3e4b74e85bb7790442096b032e7bb5ea96d9dc2ad97d24f86
sha512: 508050b5ea68eff7eaaac1301f228dbed7e01e84342858037e286ece6b3c450e202a9b1f809e4518529b1b87218addd6abda621b7067776b1ab8bebab8dabdc8
ssdeep: 12288:wMcacE7+U5RyKETLgS0bskxpVehVzmacEuh+e8:wkcorW05ehVtcBt8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Tsukishima Monja Kkoboreya
FileVersion: 1.00
CompanyName: Hawaiian Style
ProductName: Tsukishima Monja Kkoboreya
ProductVersion: 1.00
FileDescription: AGBO Business Architecture S.L.
OriginalFilename: Tsukishima Monja Kkoboreya.exe

Win32/Injector.ENKS also known as:

MicroWorld-eScanTrojan.GenericKD.43896119
ALYacTrojan.GenericKD.43896119
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056f84b1 )
BitDefenderTrojan.GenericKD.43896119
K7GWTrojan ( 0056f84b1 )
TrendMicroTROJ_GEN.R002C0DIR20
CyrenW32/VBKrypt.AOJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Vebzenpak.aaoj
AlibabaTrojan:Win32/Vebzenpak.6756769b
NANO-AntivirusTrojan.Win32.Vebzenpak.hwgqan
AegisLabTrojan.Win32.Vebzenpak.4!c
RisingTrojan.Kryptik!1.C606 (CLASSIC)
Ad-AwareTrojan.GenericKD.43896119
EmsisoftTrojan.GenericKD.43896119 (B)
F-SecureTrojan.TR/Kryptik.izqjv
DrWebTrojan.DownLoader34.51669
InvinceaMal/Generic-S
McAfee-GW-EditionTrickbot-FSTA!DD6076DC3359
MaxSecureTrojan.Malware.107178510.susgen
FireEyeGeneric.mg.dd6076dc3359bb7f
SophosMal/Generic-S
IkarusTrojan-Banker.Emotet
JiangminTrojan.Vebzenpak.hrf
AviraTR/Kryptik.izqjv
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Vebzenpak
MicrosoftTrojan:Win32/EmotetCrypt.PEF!MTB
ArcabitTrojan.Generic.D29DCD37
ZoneAlarmTrojan.Win32.Vebzenpak.aaoj
GDataTrojan.GenericKD.43896119
AhnLab-V3Trojan/Win32.Emotet.R352286
McAfeeTrickbot-FSTA!DD6076DC3359
TACHYONTrojan/W32.VB-Vebzenpak.540672
VBA32TScope.Trojan.VB
MalwarebytesTrojan.MalPack.TRE
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ENKS
TrendMicro-HouseCallTROJ_GEN.R002C0DIR20
TencentMalware.Win32.Gencirc.10ce0625
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.ESZW!tr
BitDefenderThetaGen:NN.ZevbaF.34254.Hm0@a4Zd0Tck
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.c25

How to remove Win32/Injector.ENKS?

Win32/Injector.ENKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment