Malware

Win32/Packed.EnigmaProtector.L suspicious removal instruction

Malware Removal

The Win32/Packed.EnigmaProtector.L suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.EnigmaProtector.L suspicious virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Packed.EnigmaProtector.L suspicious?


File Info:

crc32: B116A896
md5: e179be1fb522384e61c12d2a2c0f5ccf
name: E179BE1FB522384E61C12D2A2C0F5CCF.mlw
sha1: 7197930696eac817a4f76d17a327c45db1ba2362
sha256: 2c9a4ffe8a00181a77a15383a4e97ec256272f1f10c891eb380edf21ed902951
sha512: e66d7c59fad9c6394bfa6bda25d09cc98f262b1fe3f4444a465ec1f44846114c62464d25530cfc8d01edb2fc1f3ae9b282394da4ba97a5f1f9168a24a9aa50d7
ssdeep: 24576:S2LdLO8anOvs+yc0HAv1nu1iuRserTItGFz+8Ig84:BBUeytHQnCHRfrTIzjgF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrights (C) 2002-2009 Vladimir Sukhov
InternalName: ENIGMA.EXE
FileVersion: 1.0.0.0
CompanyName: The Enigma Protector Developers Team
LegalTrademarks: Trademarks (R) 2002-2009 Vladimir Sukhov
Comments: http://enigmaprotector.com/
ProductName: The Enigma Protector
ProductVersion: 1.0.0.0
FileDescription: Software Protection Tool
OriginalFilename: enigma.exe
Translation: 0x0409 0x04b0

Win32/Packed.EnigmaProtector.L suspicious also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004ba83b1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaPacked:Win32/EnigmaProtector.583ff91f
K7GWTrojan ( 004ba83b1 )
Cybereasonmalicious.696eac
CyrenW32/Trojan.FFG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.L suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Bulz-9854835-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Agent.dalvgo
TencentWin32.Trojan.Generic.Aiht
SophosGeneric ML PUA (PUA)
ComodoMalware@#3llx60a43jhg
BitDefenderThetaGen:NN.ZexaF.34170.bz0@aO7@LZgi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.e179be1fb522384e
SentinelOneStatic AI – Malicious PE
AviraTR/Agent.1071104.6
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASBOL.C669
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
McAfeeArtemis!E179BE1FB522
MAXmalware (ai score=100)
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
YandexTrojan.Agent!L/uWOcTpiRk
IkarusPacker.Enigma
FortinetMSIL/Bladabindi_G.gen
AVGWin32:Malware-gen

How to remove Win32/Packed.EnigmaProtector.L suspicious?

Win32/Packed.EnigmaProtector.L suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment