Malware

Should I remove “ML/PE-A + Mal/MSIL-QK”?

Malware Removal

The ML/PE-A + Mal/MSIL-QK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/MSIL-QK virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine ML/PE-A + Mal/MSIL-QK?


File Info:

name: 8A0AF6D494BDCCBF3FA5.mlw
path: /opt/CAPEv2/storage/binaries/3f66c80f6170850e4704ec0f00fa7e4dcef2f26a2fef099289c0688bcab13cf1
crc32: C9B07583
md5: 8a0af6d494bdccbf3fa5f5feceaa1501
sha1: 49f703b25cb109e7a0b49433d1f2d04743bf279a
sha256: 3f66c80f6170850e4704ec0f00fa7e4dcef2f26a2fef099289c0688bcab13cf1
sha512: 18f467223871cd8b56867bf1fd23cf7171111fe177934d03595020a906dc0b4ff065a6feb431d0b1942d8ce2f930b307ec26f1664114d99643efabe36a3c9ac5
ssdeep: 24576:jOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO7:n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F95C58B2BE9C912C2FD93754562830903F0B6831D67E75F0DC9C4DA1F3B6544E8BAA6
sha3_384: 9802a97792dee5a64b9836460fd1c37979d09f332c760112617ddf65d18c5511a197c54beeb7bd265695036fc936a4ea
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-01-02 19:23:48

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: w.exe
LegalCopyright:
OriginalFilename: w.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

ML/PE-A + Mal/MSIL-QK also known as:

BkavW32.AIDetectNet.01
DrWebTrojan.MulDrop12.19403
MicroWorld-eScanIL:Trojan.MSILMamut.6503
FireEyeGeneric.mg.8a0af6d494bdccbf
ALYacIL:Trojan.MSILMamut.6503
CylanceUnsafe
ZillyaTrojan.Bladabindi.Win32.119430
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.494bdc
BitDefenderThetaGen:NN.ZemsilF.34646.8n3@aGWjeVd
CyrenW32/Trojan.FDS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.AZ
APEXMalicious
ClamAVWin.Trojan.Generic-6417450-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILMamut.6503
NANO-AntivirusTrojan.Win32.Bladabindi.hjsnpb
AvastMSIL:Agent-ANE [Trj]
TencentTrojan.Win32.Bladabindi.16000335
Ad-AwareIL:Trojan.MSILMamut.6503
EmsisoftTrojan.Bladabindi (A)
ComodoTrojWare.MSIL.Bladabindi.O@4thr1l
BaiduMSIL.Backdoor.Bladabindi.a
VIPREIL:Trojan.MSILMamut.6503
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/MSIL-QK
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.exsrz
GoogleDetected
AviraTR/Agent.bindub
Antiy-AVLTrojan/Generic.ASMalwS.3DAC
MicrosoftBackdoor:MSIL/Bladabindi.AL
ArcabitIL:Trojan.MSILMamut.D1967
GDataMSIL.Trojan-Spy.Keylogger.NOM8TP
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Nitol.C1690885
Acronissuspicious
McAfeeTrojan-FIGN
MAXmalware (ai score=84)
VBA32Malware-Cryptor.MSIL.AgentTesla.Heur
MalwarebytesTrojan.Agent.MSIL
RisingBackdoor.Bot!1.6675 (CLASSIC)
YandexTrojan.Bladabindi!xt8aVuQldTI
IkarusTrojan-Spy.HawkEye
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Agent.PPW!tr
AVGMSIL:Agent-ANE [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Mal/MSIL-QK?

ML/PE-A + Mal/MSIL-QK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment