Malware

ML/PE-A + CXrep/MalGo-A removal guide

Malware Removal

The ML/PE-A + CXrep/MalGo-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + CXrep/MalGo-A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.
  • CAPE detected the CobaltStrikeBeacon malware family

How to determine ML/PE-A + CXrep/MalGo-A?


File Info:

name: DA5B089DED8ED3FC3C98.mlw
path: /opt/CAPEv2/storage/binaries/81bb7b437122a7417846cfbcd50912c7c2c8267b0118cff0108e02e14a05c4a5
crc32: 1C7749F8
md5: da5b089ded8ed3fc3c98a7992668a4ff
sha1: cced02499a0dba76c2a402202aa639c7686b19b9
sha256: 81bb7b437122a7417846cfbcd50912c7c2c8267b0118cff0108e02e14a05c4a5
sha512: b10da515a219470ce7ec32650b8da405dbf9bc91435927a7fc02505b0b7cc024d3f4ef69f0fcade0d07ec6e9a67bd28ff4c6ab69babfcf7daaf5f7e081600dc2
ssdeep: 196608:dvg6YpjCa8BMHwNuD7PKUNwabNJvmrMQwHEFoWpE:dYXpkG6uDBuQjmrOHN
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T18BB67C27F5A204FDC67FD17082979732BA31786942307BAB1B90DA752F12F906B2E714
sha3_384: b31920b0b7e5e4f0952767d0a1e5cec3f8243b684f48823f1085524d1ebf9e0f6f670292787a086feb5f8bf778090bb5
ep_bytes: 4883ec28488b0535339900c700000000
timestamp: 2019-09-18 19:41:21

Version Info:

0: [No Data]

ML/PE-A + CXrep/MalGo-A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.207769
FireEyeGeneric.mg.da5b089ded8ed3fc
McAfeePUP-HXQ
CylanceUnsafe
ZillyaTrojan.FilecoderGen.Win32.2
SangforMiner.Win32.Razy_1929.se2
K7AntiVirusTrojan ( 005582711 )
AlibabaMalware:Win32/km_2500e1.None
K7GWTrojan ( 005582711 )
Cybereasonmalicious.ded8ed
CyrenW64/S-2ab76a9c!Eldorado
SymantecMeterpreter
ESET-NOD32a variant of Win64/CoinMiner.PR potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.CobaltStrike-8091534-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Bulz.207769
NANO-AntivirusTrojan.Win32.Cometer.eqcglk
AvastWin32:HacktoolX-gen [Trj]
TencentMalware.Win32.Gencirc.10b0cdcf
Ad-AwareGen:Variant.Bulz.207769
EmsisoftGen:Variant.Bulz.207769 (B)
ComodoMalware@#31ga51o81ayd6
DrWebTrojan.Siggen8.17135
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.Win64.MALXMR.SMTHOLA
McAfee-GW-EditionBehavesLike.Win64.Generic.vh
SophosML/PE-A + CXrep/MalGo-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PornoAsset.gdh
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2C5DCF2
MicrosoftTrojan:Win64/DisguisedXMRigMiner
GDataGen:Variant.Bulz.207769
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win64.CoinMiner.R292237
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.34294.mu4@au9HqIoi
ALYacGen:Variant.Bulz.207769
MAXmalware (ai score=84)
VBA32Trojan.Cometer
MalwarebytesTrojan.MalPack.VAK
TrendMicro-HouseCallCoinminer.Win64.MALXMR.SMTHOLA
RisingBackdoor.CobaltStrike!1.CEA8 (CLASSIC)
YandexTrojan.GenAsa!R4HqLR2Dbqc
IkarusWorm.Win64.FileCrypter
eGambitTrojan.Generic
FortinetW64/CoinMiner.J!worm
AVGWin32:HacktoolX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.121218.susgen

How to remove ML/PE-A + CXrep/MalGo-A?

ML/PE-A + CXrep/MalGo-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment