Malware

Win32/Injector.ENPF (file analysis)

Malware Removal

The Win32/Injector.ENPF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENPF virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.ENPF?


File Info:

crc32: C93D5234
md5: 5425d8aa1b2c9d911a31bbead7575653
name: upload_file
sha1: 8316290854a2a7a42d6fbe3392e892f9748f70ff
sha256: 0cb22d3d57812fd7f79b93f77efe33302e171b29f540f3883239f31228966a17
sha512: 299a96331d5a4697b96e8fe03b39910c4794110c45ff4869166c562ac92799115fc2eee70e26e892c93644ef8072595bfcfdc3b5d6bb40665028dc780661e115
ssdeep: 12288:40vjWj3aKV1KBGJ7AEQi+95fd32koDTmWOuW3vvJAF7SPHQ4ElujsJTfKm88S3MF:/qjKIUe7QLkbDTMrvSSwBisJL4Af2FG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copkk d Softare Corp.
InternalName:
FileVersion: 6.0
CompanyName: BrlanSre Co.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 6.0
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Win32/Injector.ENPF also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34722712
FireEyeGeneric.mg.5425d8aa1b2c9d91
McAfeeFareit-FZN!5425D8AA1B2C
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34722712
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.854a2a
TrendMicroTrojan.Win32.WACATAC.USMANJ920
CyrenW32/Trojan.SKYF-1315
SymantecInfostealer.Lokibot!43
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Keylogger.Lokibot-9775682-0
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Lokibot.c3eedbe6
TencentWin32.Trojan.Kryptik.Staj
Ad-AwareTrojan.GenericKD.34722712
SophosTroj/Steale-AKL
ComodoMalware@#yb4yumrdzb6p
DrWebBackDoor.SpyBotNET.25
InvinceaMal/Generic-S + Troj/Steale-AKL
McAfee-GW-EditionFareit-FZN!5425D8AA1B2C
EmsisoftTrojan.GenericKD.34722712 (B)
MaxSecureTrojan.Malware.73736783.susgen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Lokibot.CA!MTB
ArcabitTrojan.Generic.D211D398
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataTrojan.GenericKD.34722712
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.C4205041
BitDefenderThetaGen:NN.ZelphiF.34566.dH0@ammQBZii
ALYacTrojan.GenericKD.34722712
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
ZonerTrojan.Win32.95727
ESET-NOD32a variant of Win32/Injector.ENPF
TrendMicro-HouseCallTrojan.Win32.WACATAC.USMANJ920
RisingTrojan.Injector!1.CD4A (CLASSIC)
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.ENOR!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.469

How to remove Win32/Injector.ENPF?

Win32/Injector.ENPF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment