Malware

ML/PE-A + Mal/Antavmu-A malicious file

Malware Removal

The ML/PE-A + Mal/Antavmu-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Antavmu-A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine ML/PE-A + Mal/Antavmu-A?


File Info:

name: 104B63D2027F7CDAAC72.mlw
path: /opt/CAPEv2/storage/binaries/a6e1648efc4bcd5702dcba3de21646f7bedbd340970cdea273c96d9a16671a97
crc32: 6DFB3FAC
md5: 104b63d2027f7cdaac72a0ba92cb7270
sha1: 66525d111c0edc591991b69fca703bbb7079bd87
sha256: a6e1648efc4bcd5702dcba3de21646f7bedbd340970cdea273c96d9a16671a97
sha512: ca5e7a47a616bdabc3bea0c88afa04c0de4a42280ea545a02f58f38c8fb4a59d2b5309f43321dae915af192530e3ac6947da64b5612af3733abc53134dff84bc
ssdeep: 1536:68WfnMzlJ62Dp76vRFzUrTgZQoPigFGcG995sNI:68WPS8dUrTA87
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F5737C137BD0C174E40A83747A786F73DE7DFA20275621A2A3B0A7255F75280EA0736B
sha3_384: 9be72674fd261876d9fb8aa94796b5ba9556a9268fba0d962c7bc417217a0b54e32f1e7408b7ddc0c25038d5e0fb084c
ep_bytes: a1dbf04000c1e002a3dff04000575133
timestamp: 2042-11-21 16:01:10

Version Info:

0: [No Data]

ML/PE-A + Mal/Antavmu-A also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.28628
MicroWorld-eScanGen:Trojan.FileInfector.eCW@aOPHzki
FireEyeGeneric.mg.104b63d2027f7cda
CAT-QuickHealTrojan.Antavmu.D7
ALYacGen:Trojan.FileInfector.eCW@aOPHzki
CylanceUnsafe
K7AntiVirusTrojan ( 001f4e2b1 )
AlibabaTrojan:Win32/Antavmu.2835277c
K7GWTrojan ( 001f4e2b1 )
Cybereasonmalicious.2027f7
BitDefenderThetaAI:Packer.1889BCA41E
VirITTrojan.Win32.Generic.BUNO
CyrenW32/Antavmu.A.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/KillFiles.NEH
APEXMalicious
ClamAVWin.Virus.Fileinfector-9809043-0
KasperskyTrojan.Win32.Agent.idez
BitDefenderGen:Trojan.FileInfector.eCW@aOPHzki
NANO-AntivirusTrojan.Win32.Drop.cihufp
SUPERAntiSpywareTrojan.Agent/Gen-Antavmu
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b3c199
TACHYONTrojan/W32.Antavmu.73728.H
SophosML/PE-A + Mal/Antavmu-A
ComodoTrojWare.Win32.KillFiles.NEH@4qfvz0
VIPRETrojan.Win32.Antavmu.d (v)
TrendMicroTROJ_AGENT_055244.TOMB
McAfee-GW-EditionPWS-OnlineGames.kz
EmsisoftGen:Trojan.FileInfector.eCW@aOPHzki (B)
IkarusTrojan.Win32.KillFiles
JiangminTrojan.Antavmu.bxc
AviraTR/Antavmu.doue
Antiy-AVLTrojan/Generic.ASMalwS.138E36
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Trojan.FileInfector.eCW@aOPHzki
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Antavmu.R25058
McAfeePWS-OnlineGames.kz
MAXmalware (ai score=84)
VBA32Trojan.Antavmu
MalwarebytesMalware.AI.2897677066
TrendMicro-HouseCallTROJ_AGENT_055244.TOMB
RisingTrojan.Win32.Antavmu.c (RDMK:cmRtazqxLWBcXp+g3gaHGcTrgw8e)
YandexTrojan.GenAsa!UVM9UIzqgzk
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/BanLoader.BBCF!worm
AVGWin32:TrojanX-gen [Trj]

How to remove ML/PE-A + Mal/Antavmu-A?

ML/PE-A + Mal/Antavmu-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment