Malware

ML/PE-A + Mal/EncPk-ABFO malicious file

Malware Removal

The ML/PE-A + Mal/EncPk-ABFO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/EncPk-ABFO virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • The executable is likely packed with VMProtect
  • Attempts to stop active services
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Collects information to fingerprint the system

Related domains:

catsdegree.com

How to determine ML/PE-A + Mal/EncPk-ABFO?


File Info:

crc32: 7A134BF4
md5: b40d2f071e74407c6b0c233438eec792
name: B40D2F071E74407C6B0C233438EEC792.mlw
sha1: 7ae3e3890442722400988ec34debee21196db7ca
sha256: 301a6047f0be178f1fa567406853b0a5604bc57d372ef2769e439f26ecd5469a
sha512: da2137ba8e19b6a94465044e617de4bb23d0f04f6c6588b7c8fa99413a87ac032cf44027f47ed10b3af43dee3c92cbf97f755eba68b4b67d2d6a1bd2d3337265
ssdeep: 768:biTjagICPhDt3bS4nyzGCuwSbV5dNcxGV1yldoZT+rcAvVtFmWeKgH/DH8Y23W5:OpDtG4nM5boDTV1yl++rftFmWlwLnZ5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Mal/EncPk-ABFO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000001c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33499
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.RTH.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.71e744
ESET-NOD32a variant of Win32/Filecoder.DarkSide.A
APEXMalicious
AvastWin32:DarkSide-C [Ransom]
ClamAVWin.Packed.DarkSide-9262656-0
KasperskyHEUR:Trojan-Ransom.Win32.Darkside.gen
BitDefenderGen:Heur.Ransom.RTH.1
MicroWorld-eScanGen:Heur.Ransom.RTH.1
Ad-AwareGen:Heur.Ransom.RTH.1
SophosML/PE-A + Mal/EncPk-ABFO
BitDefenderThetaAI:Packer.3E8D52B61E
TrendMicroRansom.Win32.DARKSIDE.SMYAAK-B
McAfee-GW-EditionGenericRXNS-CM!B40D2F071E74
FireEyeGeneric.mg.b40d2f071e74407c
EmsisoftGen:Heur.Ransom.RTH.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gttmr
AviraHEUR/AGEN.1137758
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.3174E0B
MicrosoftRansom:Win32/DarkSide.DA
ArcabitTrojan.Ransom.RTH.1
ZoneAlarmHEUR:Trojan-Ransom.Win32.Darkside.gen
GDataGen:Heur.Ransom.RTH.1
AhnLab-V3Trojan/Win.Ransom.R419377
McAfeeGenericRXNS-CM!B40D2F071E74
MAXmalware (ai score=85)
VBA32BScope.Trojan.Diple
MalwarebytesRansom.DarkSide
TrendMicro-HouseCallRansom.Win32.DARKSIDE.SMYAAK-B
RisingTrojan.Generic@ML.81 (RDML:+K68xpH2tc8U51i89voCUA)
IkarusTrojan-Ransom.DarkSide
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:DarkSide-C [Ransom]
Qihoo-360HEUR/QVM16.0.2676.Malware.Gen

How to remove ML/PE-A + Mal/EncPk-ABFO?

ML/PE-A + Mal/EncPk-ABFO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment