Malware

Win32/Packed.Enigma.AAF removal guide

Malware Removal

The Win32/Packed.Enigma.AAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Enigma.AAF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Packed.Enigma.AAF?


File Info:

name: 7535494CEB62F52A23B4.mlw
path: /opt/CAPEv2/storage/binaries/4b908cb5f3523969e94ce24b52da4990e34a7a5808ca78458154d6032f77ddfc
crc32: 407DBBBD
md5: 7535494ceb62f52a23b4c27256a79957
sha1: 2dcd43321bdb53ba286d270ea5ea6e801065e777
sha256: 4b908cb5f3523969e94ce24b52da4990e34a7a5808ca78458154d6032f77ddfc
sha512: a0a44fc776a51c312a926ccef35f0a3566ab1856409e148fca62abf163a4e6d872cb2d85f900c06b779dc3244d677141606ce2b1219d270e6372c82eb27627cd
ssdeep: 24576:3rIoARaZGD2fkFzf+QIcZH2lwQMBaWnBCqyQQj/Al7symGR:7Rh2zf+owlMBaWnt/d7JmG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF4523F406BF9E00E45F33B900426A54A647BD9396082A6DB66BF84E4FFC8FD9752D01
sha3_384: ca87405767de0ac2e0b199aa63aa880cd69c85a7d93274bf5ad9776491f59014be6e23af47ca665e916729a3bdb0cc31
ep_bytes: 60e8000000005d81ed0600000081ed04
timestamp: 2024-01-20 12:42:03

Version Info:

0: [No Data]

Win32/Packed.Enigma.AAF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lwTF
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.105142
FireEyeGeneric.mg.7535494ceb62f52a
SkyhighBehavesLike.Win32.Dropper.tc
McAfeeArtemis!7535494CEB62
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.21bdb5
ArcabitTrojan.Generic.D19AB6
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Enigma.AAF
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Scar-6903585-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKDZ.105142
AvastWAT:Blacked-E
EmsisoftTrojan.GenericKDZ.105142 (B)
VIPRETrojan.GenericKDZ.105142
SophosMal/Generic-S
IkarusVirus.Win32.Heur
VaristW32/Threat-HLLIE-based!Maximus
Antiy-AVLTrojan[Packed]/Win32.Enigma
MicrosoftTrojan:Win32/Caynamer.A!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.1LKL057
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36680.jHW@a4MqGcpk
ALYacTrojan.GenericKDZ.105142
VBA32BScope.Trojan.Bitrep
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
AVGWAT:Blacked-E
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Packed.Enigma.AAF?

Win32/Packed.Enigma.AAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment