Malware

What is “Win32/Injector.ENQB”?

Malware Removal

The Win32/Injector.ENQB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENQB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.ENQB?


File Info:

crc32: B77CAA74
md5: e75cf56236168f6d98425f13658737b6
name: test.exe
sha1: 0ce6559d857175bcc007cdda6c3fca2c7d7dc6ba
sha256: 661f94e6edb8ac51fd9b7831a45102586aec2fb596ca799c709b806784ff0785
sha512: 2d1368464dd1161ea9a505e41d87e8a9d9b6ce83d9591dc2f8896c490a721e5291c139240249b1a9fcfef62ecf398069fe830f3cc47008f097fa907be16ced19
ssdeep: 1536:MdzXTgeNnMKunOONLvUaZZ801i+g6YCMFJbxtGS1645ZCD8ChZxnmZy0:MdzXTguMZnOCbh801hmfTE8ChZxnmg0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: ChillX
InternalName: Turrifer
FileVersion: 1.00
CompanyName: ChillX
LegalTrademarks: ChillX
Comments: ChillX
ProductName: ChillX
ProductVersion: 1.00
FileDescription: ChillX
OriginalFilename: Turrifer.exe

Win32/Injector.ENQB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44074256
Qihoo-360Win32/Trojan.5ce
McAfeeArtemis!E75CF5623616
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005710f51 )
BitDefenderTrojan.GenericKD.44074256
K7GWTrojan ( 005710f51 )
TrendMicroTrojan.Win32.VEBZENPAK.USMANJF20
SymantecW32.Rixobot
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.Rixobot-9778079-0
KasperskyTrojan.Win32.Vebzenpak.abbx
AlibabaTrojan:Win32/Vebzenpak.38970b1d
Ad-AwareTrojan.GenericKD.44074256
EmsisoftTrojan.Injector (A)
ComodoMalware@#3khbmgyydc573
F-SecureTrojan.TR/Injector.fyljm
DrWebTrojan.PWS.Siggen2.57329
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
FireEyeGeneric.mg.e75cf56236168f6d
SophosMal/Generic-S
AviraTR/Injector.fyljm
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Ymacco.AA35
ArcabitTrojan.Generic.D2A08510
ZoneAlarmTrojan.Win32.Vebzenpak.abbx
GDataTrojan.GenericKD.44074256
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZevbaCO.34570.km0@a4xkxqdj
ALYacTrojan.GenericKD.44074256
MAXmalware (ai score=84)
MalwarebytesTrojan.VBCrypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ENQB
TrendMicro-HouseCallTrojan.Win32.VEBZENPAK.USMANJF20
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_94%
FortinetW32/ENQB!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Win32/Injector.ENQB?

Win32/Injector.ENQB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment