Malware

ML/PE-A + Mal/FareitVB-I removal tips

Malware Removal

The ML/PE-A + Mal/FareitVB-I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/FareitVB-I virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Czech
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Mal/FareitVB-I?


File Info:

crc32: ED701FFF
md5: 2dabe28babd57abb5ff5854bdefe65ff
name: 2DABE28BABD57ABB5FF5854BDEFE65FF.mlw
sha1: 69d81c104bd8bb4953319b2df04b21dc1ae428f0
sha256: 4b611d0f1bcb7daca27c3093c8c7ea6359e5b6e5b6b4c91e4cba798f60b3413c
sha512: b060ff2c03532a1894b3806ec8ebee7d9e427bcc695134804ae44c30a3044958cea31d65b07f201132428b2d61934db348f613c7c9e5af3ec874e6e3bb898b8a
ssdeep: 24576:ecCT67wHqWis4l+jIACFr5hqjiLDpSJDN93pqb6W8cU4gLQlA:3Cpn8t74iA3qb6W8cU4Y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0405 0x04b0
InternalName: Braggat0
FileVersion: 1.09.0005
CompanyName: Windows
Comments: Geacata
ProductName: Orphancy
ProductVersion: 1.09.0005
FileDescription: Geacata
OriginalFilename: Braggat0.exe

ML/PE-A + Mal/FareitVB-I also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00502b1a1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.55368
CynetMalicious (score: 100)
ALYacTrojan.Agent.DXTX
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.302131
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/VBKrypt.32c
K7GWTrojan ( 00502b1a1 )
Cybereasonmalicious.babd57
CyrenW32/Injector.YKAB-2853
SymantecW32.Tapin
ESET-NOD32Win32/AutoRun.Delf.LV
ZonerTrojan.Win32.82457
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Trojan.VBGeneric-6989114-0
KasperskyTrojan.Win32.VBKrypt.xupa
BitDefenderTrojan.Agent.DXTX
NANO-AntivirusTrojan.Win32.VBKrypt.ewdbrj
ViRobotTrojan.Win32.Agent.1576960.B
MicroWorld-eScanTrojan.Agent.DXTX
TencentMalware.Win32.Gencirc.10b09472
Ad-AwareTrojan.Agent.DXTX
SophosML/PE-A + Mal/FareitVB-I
ComodoTrojWare.Win32.Fareit.RGY@7qlz41
F-SecureHeuristic.HEUR/AGEN.1126331
BitDefenderThetaAI:Packer.D6236ABB21
TrendMicroTSPY_HPFAREIT.SME
McAfee-GW-EditionBehavesLike.Win32.DistTrack.tm
FireEyeGeneric.mg.2dabe28babd57abb
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VBKrypt.cgtc
AviraHEUR/AGEN.1126331
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Win32.VBKrypt
MicrosoftVirTool:Win32/VBInject.YA!MTB
GridinsoftTrojan.Win32.Kryptik.ka!s1
ArcabitTrojan.Agent.DXTX
SUPERAntiSpywareTrojan.Agent/Gen-PonyStealer
ZoneAlarmTrojan.Win32.VBKrypt.xupa
GDataTrojan.Agent.DXTX
TACHYONTrojan/W32.VB-VBKrypt.1576960.B
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeDistTrack!2DABE28BABD5
MAXmalware (ai score=86)
VBA32Trojan.VBKrypt
MalwarebytesQbot.Backdoor.Stealer.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_HPFAREIT.SME
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!z1jxJcx+Gmw
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.11806882.susgen
FortinetW32/Injector.DJYO!tr
AVGWin32:TrojanX-gen [Trj]
Qihoo-360HEUR/QVM03.0.4DCA.Malware.Gen

How to remove ML/PE-A + Mal/FareitVB-I?

ML/PE-A + Mal/FareitVB-I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment