Malware

Downldr.Freepds.MUE.ZZ5 removal

Malware Removal

The Downldr.Freepds.MUE.ZZ5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downldr.Freepds.MUE.ZZ5 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Downldr.Freepds.MUE.ZZ5?


File Info:

crc32: 37355555
md5: b14d36c6dd1fe109f42a2b1ba736207e
name: B14D36C6DD1FE109F42A2B1BA736207E.mlw
sha1: 68230e1086841ee4209a30904b3ff12ec5f59fa2
sha256: 9a323aa599bf998ebb764a751dc2228abb515d9c29f08666e37a58c47b5bb196
sha512: fe25caed6a5d39ed9c2a313f19677852a3eeae1ecaa3a21f10784755968ada875a7f76e69ae3dce2b5659e72519b53773cf755745ac4ee8d21653182c5275bdb
ssdeep: 3072:V0PVzo3odTe1loPTvbWzuEHviWBlG492R0No5lMBLXnJ:V7Ys1loLvbGiwQ482NoQBLX
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: cmd
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Downldr.Freepds.MUE.ZZ5 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f94ca1 )
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1313641
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Exxroute.25f1208f
K7GWTrojan ( 004f94ca1 )
Cybereasonmalicious.6dd1fe
CyrenW32/S-ef537a26!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Agent.pef
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.evpxut
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentWin32.Trojan.Ransom.Pcin
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34686.gy0@auBqkKeU
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.b14d36c6dd1fe109
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188296
Acronissuspicious
McAfeeGenericRXAA-AA!B14D36C6DD1F
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.929094131
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingRansom.Tovicrypt!8.9F4B (CLOUD)
YandexTrojan.Agent!ezc5nptLdOI
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Downldr.Freepds.MUE.ZZ5?

Downldr.Freepds.MUE.ZZ5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment