Malware

ML/PE-A + Mal/AuItInj-A (file analysis)

Malware Removal

The ML/PE-A + Mal/AuItInj-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/AuItInj-A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/AuItInj-A?


File Info:

crc32: F4A9CEF4
md5: 91731e95e8f4be683efc909b0f932958
name: 91731E95E8F4BE683EFC909B0F932958.mlw
sha1: 35ef2e58df1d9c2bb164701d930f69a469a9f383
sha256: 3ae5425033502bba7f7b8c7498573f7ca17e7e98e14288f734adb1a5af19318d
sha512: 2663840ed55082d73dac99f8a1484407c6a73d9ce50ba22134c815c7a66287acdde6aaaf93ebf7ecc13dbe36ff62108e90b63c4ddbea0c6208bdacb2aed75831
ssdeep: 24576:yAHnh+eWsN3skA4RV1Hom2KXMmHaLIahgxY3b5:1h+ZkldoPK8YaLDN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: winver
FileVersion: 385.28.742.705
CompanyName: control
ProductName: CameraCaptureUI
ProductVersion: 130.164.941.861
FileDescription: AudioEndpointBuilder
OriginalFilename: FlashUtil64_31_0_0_153_Plugin.exe
Translation: 0x0409 0x04b0

ML/PE-A + Mal/AuItInj-A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43301293
FireEyeGeneric.mg.91731e95e8f4be68
CAT-QuickHealTrojan.Autoit
McAfeeArtemis!91731E95E8F4
MalwarebytesBackdoor.Remcos
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00549f261 )
BitDefenderTrojan.GenericKD.43301293
K7GWTrojan ( 00549f261 )
Cybereasonmalicious.5e8f4b
CyrenW32/AutoIt.TJ.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
ClamAVWin.Malware.Autoit-6985962-0
KasperskyHEUR:Trojan.Script.Generic
AlibabaVirTool:Win32/AutInject.016c73f5
ViRobotTrojan.Win32.Z.Autoit.1179648.B
AegisLabHacktool.Win32.Gamehack.3!e
Ad-AwareTrojan.GenericKD.43301293
EmsisoftTrojan.GenericKD.43301293 (B)
ComodoTrojWare.Win32.AutoIt.SS@8sg957
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.Inject3.16009
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
SophosML/PE-A + Mal/AuItInj-A
IkarusTrojan.Autoit
AviraDR/AutoIt.Gen8
Antiy-AVLGrayWare/Autoit.ShellCode.a
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/AutInject.CZ!bit
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D294B9AD
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.43301293
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
ALYacTrojan.GenericKD.43301293
MAXmalware (ai score=86)
VBA32Backdoor.Remcos
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.AutoIt.SS
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
TencentMalware.Win32.Gencirc.10b0d10f
FortinetAutoIt/Injector.DWD!tr
AVGAutoIt:Injector-JF [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.a43

How to remove ML/PE-A + Mal/AuItInj-A?

ML/PE-A + Mal/AuItInj-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment