Malware

Win32/Packed.Enigma.N (file analysis)

Malware Removal

The Win32/Packed.Enigma.N is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Enigma.N virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Packed.Enigma.N?


File Info:

crc32: 10EAED04
md5: d494b4e1efc70415a104e43e29c34016
name: D494B4E1EFC70415A104E43E29C34016.mlw
sha1: 083e9610cb54cda62e379b01f8bef013272f57d0
sha256: 89b567b07a6d02e647cbad07d01ecb723dedd8095a84c8080ecf6f8c2b6ace09
sha512: dcf4917243ebec055f9d6e08609f9e217212d107a3e4272c143d024e32605aebe05a71b41a105472768232f03a4b7e6212a90d258e2d81d0f1d411104b19d8f7
ssdeep: 24576:yrRUi8rCHx+UMEcmdDebQcmfnJ3IuSMwK6sz2LKXB8R5lsN3pqANMTUr7zAnBr:6UDWAUMqwbQ7nJ3IwF64LBG5ls1MTUD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: w.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: w.exe

Win32/Packed.Enigma.N also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
ClamAVWin.Ransomware.Locky-5880884-0
CylanceUnsafe
ZillyaTrojan.Locky.Win32.2490
SangforTrojan.Win32.Ransom-Locky.8
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 00502b341 )
K7AntiVirusTrojan ( 00502b341 )
CyrenW32/Trojan.CFBD-5917
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Enigma.N
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Locky.xcj
NANO-AntivirusTrojan.Win32.GenericKD.ekqulk
TencentWin32.Trojan.Locky.Wrge
SophosMal/Generic-S
ComodoMalware@#2tryr8kgkrs4p
BitDefenderThetaGen:NN.ZexaF.34670.ED0@aG5aHbe
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.d494b4e1efc70415
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Locky.ddu
AviraTR/Dropper.MSIL.Gen
Antiy-AVLGrayWare/Win32.EnigmaProtect.a
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Locky.A
TACHYONRansom/W32.Locky.1555968
Acronissuspicious
McAfeeArtemis!D494B4E1EFC7
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKY.F117AJ
RisingTrojan.Ransom-Locky!8.4655 (CLOUD)
YandexTrojan.Locky!SEKubEM8hrM
IkarusTrojan.Win32.Inject
FortinetGenerik.LUIVROW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HgAASRUA

How to remove Win32/Packed.Enigma.N?

Win32/Packed.Enigma.N removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment