Malware

How to remove “ML/PE-A + Mal/Kryptik-DQ”?

Malware Removal

The ML/PE-A + Mal/Kryptik-DQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Kryptik-DQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Mal/Kryptik-DQ?


File Info:

crc32: 94271F88
md5: 25eb4c68cabd48563ded9fff6f275c4d
name: 25EB4C68CABD48563DED9FFF6F275C4D.mlw
sha1: 17b1bfc16e30aaaab5651118d010c1bb087af32f
sha256: 0bd4f74a5502fe6fdbc1f1e4a1e8ddd99e4499327fe247d668823e350f2b12e6
sha512: 3b7dee644adfeb3eb6636515f8124a79383b0d9d6a04ebcbbecfa304e36c93972f6687ffc08201c98858ce2fbd08e6a8c2ae33beaa4c758aabde5e81647f0ff7
ssdeep: 3072:iAkzrvTXX6m6acOf1QwRBsdeUb8Oy7YuLg0Gjj5D:WvvbLdRAesA7YU2
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2018
InternalName: oe2hrfl
FileVersion: 40.488.0.00
Full Version: 40.488.0.00
CompanyName: Oracle Corporation
ProductName: Oeoh(FL) Hnrtunon ID 8 O172
ProductVersion: 4.0.0000.00
FileDescription: Java(TM) Platform SE binary
OriginalFilename: oe2hrfl.dll
Translation: 0x0409 0x04b0

ML/PE-A + Mal/Kryptik-DQ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.797307
FireEyeGeneric.mg.25eb4c68cabd4856
ALYacGen:Variant.Razy.797307
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.797307
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZedlaF.34670.ku8@ayScGwdi
CyrenW32/Kryptik.CPO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHXS
APEXMalicious
RisingTrojan.Generic@ML.84 (RDML:XvnK4o7ICk/C9DmcBMpqYA)
Ad-AwareGen:Variant.Razy.797307
SophosML/PE-A + Mal/Kryptik-DQ
F-SecureTrojan.TR/Crypt.Agent.exwrv
McAfee-GW-EditionDrixed-FJX!25EB4C68CABD
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.exwrv
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Agent.oa!s3
ArcabitTrojan.Razy.DC2A7B
GDataGen:Variant.Razy.797307
CynetMalicious (score: 100)
Acronissuspicious
McAfeeDrixed-FJX!25EB4C68CABD
MalwarebytesTrojan.Agent
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HHXS!tr
Qihoo-360Generic/HEUR/QVM40.1.B2A9.Malware.Gen

How to remove ML/PE-A + Mal/Kryptik-DQ?

ML/PE-A + Mal/Kryptik-DQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment