Malware

ML/PE-A + ATK/FatRat-H removal instruction

Malware Removal

The ML/PE-A + ATK/FatRat-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + ATK/FatRat-H virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + ATK/FatRat-H?


File Info:

crc32: F980F3AA
md5: c86477d866634755d8be3d2e8f06013a
name: C86477D866634755D8BE3D2E8F06013A.mlw
sha1: afb0d0a789e0e93f0f0ed037e8830b7dc0dbd188
sha256: d5a83126427eebfa66ae096bcff40269296ee7ab9b0777eac95316fabc65014f
sha512: 11b320881d1aafaf9d50702698e575bd4983e25603cbab53e9ee98b9b07c24091b0587ebb33845ef2847d247a52cbe46211b46610eedddf7386f06c500d2e498
ssdeep: 384:UEEoLO56ayzcMj+XHdpLBxqNwdcYyINex257s:XE8O56lcVWwdcDINes7s
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x007f 0x04b0
LegalCopyright:
InternalName: test
FileVersion: 0.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion:
FileDescription:
OriginalFilename: test.exe

ML/PE-A + ATK/FatRat-H also known as:

K7AntiVirusTrojan ( 00565ae31 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.26209
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.55567
ZillyaTrojan.Rozena.Win32.109581
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Rozena.02828f5a
K7GWTrojan ( 00565ae31 )
Cybereasonmalicious.866634
CyrenW32/Rozena.X.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Rozena.C
APEXMalicious
AvastWin32:TheFatRat-A [Trj]
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderGen:Variant.Barys.55567
MicroWorld-eScanGen:Variant.Barys.55567
TencentWin32.Trojan-downloader.Generic.Syrk
Ad-AwareGen:Variant.Barys.55567
SophosML/PE-A + ATK/FatRat-H
ComodoTrojWare.MSIL.Rozena.C@7gzixj
BitDefenderThetaGen:NN.ZemsilF.34692.bm0@auGhIJo
TrendMicroTROJ_GEN.R005C0DEP21
McAfee-GW-EditionGenericRXBH-DV!C86477D86663
FireEyeGeneric.mg.c86477d866634755
EmsisoftGen:Variant.Barys.55567 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1106254
eGambitTrojan.Generic
MicrosoftTrojan:Win32/Rozena.D!bit
GDataGen:Variant.Barys.55567
AhnLab-V3Trojan/Win32.RL_Generic.C3980343
McAfeeGenericRXBH-DV!C86477D86663
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DEP21
RisingDownloader.Generic!8.141 (CLOUD)
IkarusTrojan.PowerShell.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Rozena.G!tr
AVGWin32:TheFatRat-A [Trj]
Paloaltogeneric.ml

How to remove ML/PE-A + ATK/FatRat-H?

ML/PE-A + ATK/FatRat-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment