Malware

Should I remove “Win32/Injector.ENWT”?

Malware Removal

The Win32/Injector.ENWT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENWT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to execute a powershell command with suspicious parameter/s
  • A process created a hidden window
  • A scripting utility was executed
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.ENWT?


File Info:

crc32: 35FC9B1D
md5: c2671bf5b5dedbfd3cfe3f0f944fbe01
name: C2671BF5B5DEDBFD3CFE3F0F944FBE01.mlw
sha1: da3e830011e6f9d41dd6c93fdb48c47c1c6e35e1
sha256: 226a723ffb4a91d9950a8b266167c5b354ab0db1dc225578494917fe53867ef2
sha512: 256bc8582cc9b53b3cf9307a2882117476648ab9df540d501fc5f46a4030beacab9df2019f2d83b0a63d510803cbf6cbae01dc1325588f93a1a74521a07fe4d9
ssdeep: 1536:ssBoz9GFuIdclwKfVPoawSL20mRbg2DrE1mHkrY0f3r6fR0ZzDWR+3itGSh6ZVvg:ssS3oifBoaXhDWA4G3eeJaeIbmC00
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: BreakOut
FileVersion: 1.00
CompanyName: APCO Worldwide
Comments: HELVETAS Swiss Intercooperation
ProductName: BreakOut
ProductVersion: 1.00
OriginalFilename: BreakOut.exe

Win32/Injector.ENWT also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.Encoder.33086
ClamAVWin.Trojan.VBGeneric-9792518-0
CAT-QuickHealTrojan.Multi
Qihoo-360Generic/HEUR/QVM03.0.3561.Malware.Gen
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Vebzenpak.4!c
SangforMalware
K7AntiVirusTrojan ( 005733fd1 )
BitDefenderTrojan.GenericKD.44445993
K7GWTrojan ( 005733fd1 )
ArcabitTrojan.Generic.D2A63129
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34634.mm0@aej0kTii
CyrenW32/Trojan.XSBE-2729
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ENWT
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vebzenpak.abth
AlibabaTrojan:Win32/Vebzenpak.0530a1b0
ViRobotTrojan.Win32.S.MountLocker.204800
MicroWorld-eScanTrojan.GenericKD.44445993
Ad-AwareTrojan.GenericKD.44445993
EmsisoftTrojan.GenericKD.44445993 (B)
ComodoMalware@#13hvj5xhga2q4
ZillyaTrojan.Vebzenpak.Win32.4284
TrendMicroTROJ_GEN.R011C0PKD20
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.dm
FireEyeGeneric.mg.c2671bf5b5dedbfd
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Vebzenpak.iec
MAXmalware (ai score=100)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win32.Downloader.oa
MicrosoftVirTool:MSIL/SharPersist
ZoneAlarmTrojan.Win32.Vebzenpak.abth
GDataTrojan.GenericKD.44445993
VBA32TScope.Trojan.VB
ALYacTrojan.Ransom.Filecoder
MalwarebytesTrojan.MalPack.TRE
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0PKD20
TencentWin32.Trojan.Vebzenpak.Swkl
YandexTrojan.Vebzenpak!NLgvXObhsYA
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_99%
FortinetW32/Generik.DSYQAPK!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.ENWT?

Win32/Injector.ENWT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment