Malware

Win32/Injector.ENMD removal

Malware Removal

The Win32/Injector.ENMD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENMD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.ENMD?


File Info:

crc32: 2A2D3BC0
md5: 1bdf4969e039dce5e33bc0322e5cea21
name: de.exe
sha1: db9d0b421d01228f35154c52ee486390c9ae30af
sha256: cdae5c24bd6813de0e0c71748062db520bb43ab16a1995e9de684e2ededa9cae
sha512: 4823d9b379e1a0288fa3617527584ce4d5061ff33faf358527248bf311b230c54b594718675145a2f1266f3b03de55cf0cb210198623a7039211df4c93c9e827
ssdeep: 6144:JPCganNQkFxNN+89pM2f6nqyDglKGZrwmDkRSsD827eHOld:Han6kFMMpzf6mjZkcsD8oCOld
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Injector.ENMD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34644705
FireEyeGeneric.mg.1bdf4969e039dce5
CAT-QuickHealBackdoor.Remcos
ALYacTrojan.GenericKD.34644705
CylanceUnsafe
ZillyaBackdoor.Remcos.Win32.3093
AegisLabTrojan.Win32.Remcos.m!c
SangforMalware
K7AntiVirusTrojan ( 005702581 )
BitDefenderTrojan.GenericKD.34644705
K7GWTrojan ( 005702581 )
Cybereasonmalicious.21d012
TrendMicroBackdoor.Win32.REMCOS.THJODBO
CyrenW32/Trojan.IAXA-6977
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaBackdoor:Win32/Ymacco.577e6ddf
ViRobotTrojan.Win32.Z.Remcos.317348
Ad-AwareTrojan.GenericKD.34644705
SophosMal/Generic-S
ComodoMalware@#3plii5fnbg48e
F-SecureTrojan.TR/Injector.vvwqh
DrWebTrojan.PWS.Stealer.29393
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.Injector (A)
WebrootW32.Trojan.Gen
AviraTR/Injector.vvwqh
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Ymacco.AACD
ArcabitTrojan.Generic.D210A2E1
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataTrojan.GenericKD.34644705
CynetMalicious (score: 85)
McAfeeArtemis!1BDF4969E039
VBA32Backdoor.Remcos
MalwarebytesTrojan.Injector
ESET-NOD32a variant of Win32/Injector.ENMD
TrendMicro-HouseCallBackdoor.Win32.REMCOS.THJODBO
IkarusTrojan-Spy.FormBook
FortinetW32/Remcos!tr.bdr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.a07

How to remove Win32/Injector.ENMD?

Win32/Injector.ENMD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment