Malware

Should I remove “Win32/Packed.Enigma.AAI”?

Malware Removal

The Win32/Packed.Enigma.AAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Enigma.AAI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Sniffs keystrokes
  • Checks for the presence of known windows from debuggers and forensic tools
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
google-lc3.servegame.com

How to determine Win32/Packed.Enigma.AAI?


File Info:

crc32: 8E73FC9D
md5: 78b92b7ec321ec29bc015b8e6eb6f95f
name: 78B92B7EC321EC29BC015B8E6EB6F95F.mlw
sha1: a81b5857b67a3e762567d58d667eb20147178211
sha256: 2666147fdd90675807d632ce07bc6a54adec77e5f2dfe2fef8ce2a102c68be60
sha512: 7e0cb7e9a6d6fdd1f18e0ed55f094f4e90fdf6190e699e6db2d1ce2e9bb17ccd1da6cbe8c33cc6dbd10a9dc9156d0f21756eec5dbf25a6f52d7bf3839086de01
ssdeep: 24576:8VKwIEgO4g7gYpvEl56vynASiJmtIztxeT4viCIMdtdBq:OKmLclw6AH9z0CI4tdB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrights (C) 2002-2009 Vladimir Sukhov
InternalName: ENIGMA.EXE
FileVersion: 50.46.90.200
CompanyName: The Enigma Protector Developers Team
LegalTrademarks: Trademarks (R) 2002-2009 Vladimir Sukhov
Comments: http://enigmaprotector.com/
ProductName: The Enigma Protector
ProductVersion: 1.0.0.0
FileDescription: Software Protection Tool
OriginalFilename: enigma.exe
Translation: 0x0409 0x04b0

Win32/Packed.Enigma.AAI also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004ba83b1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader26.64844
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaDropper.Dapato.Win32.24877
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004ba83b1 )
Cybereasonmalicious.7b67a3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Enigma.AAI
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Mlw.fduyfu
TencentWin32.Backdoor.Agent.Ajvt
SophosMal/Generic-S
ComodoMalware@#4zalwn9mzgo5
BitDefenderThetaGen:NN.ZexaF.34236.pz0@a8dK@khi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.78b92b7ec321ec29
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128069
eGambitUnsafe.AI_Score_94%
MicrosoftBackdoor:MSIL/Bladabindi.AP
Acronissuspicious
McAfeeArtemis!78B92B7EC321
PandaTrj/CI.A
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
YandexTrojan.Agent!ZGTy8Iqd6NQ
IkarusTrojan.Win32.Enigma
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Packed.Enigma.AAI?

Win32/Packed.Enigma.AAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment