Malware

ML/PE-A + Mal/Tinba-V malicious file

Malware Removal

The ML/PE-A + Mal/Tinba-V is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Tinba-V virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Mimics the system’s user agent string for its own requests
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Romanian
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Uses suspicious command line tools or Windows utilities

Related domains:

ip-addr.es
myexternalip.com
curlmyip.com
crl.pki.goog
crls.pki.goog
ocsp.pki.goog
primemovies.net
forexinsuracembard.com
damozhai.com
webandnoticias.com
travancy.com
pretor.su
snocmobilya.com
doozfriend.com
zemamranews.com
handmade.co.id
befitster.com
grupointernex.com.br
nobilighting.com
sudatrain.net
thecarnivalfest.com
tamazawatokuichiro.com
rationwalaaa.com
tmp3malinium.com
sparshsewa.com
engagedforpeace.org
noblevisage.com
konstructmarketing.com
abenorbenin.com
meaarts.com
www.hugedomains.com
ocsp.digicert.com
shopshe.com
project976.org
vlsex.net
theboomerzblog.com
therealdiehls.com
perpabaskievi.net
suttonfarms.net
xn--e1asbeck.xn--p1ai
gainsenligne.info
reanimator-service.com
droidmaza.com
safepeace.com
euro-dom.de
sadefuar.com
virginia-education.com
immigrating.xsrv.jp
fengfeifei.net
icanconsultancy.org
bolle-immobilien.de
freeapkipa.com
myfacecom.com
asistent.su
descargar-facebook-messenger.com
ipmon.net
promofordbekasi.com
bookstower.com

How to determine ML/PE-A + Mal/Tinba-V?


File Info:

crc32: E0A33A47
md5: 4ff50996cd8e8ceb96f2a68b89de4787
name: 4FF50996CD8E8CEB96F2A68B89DE4787.mlw
sha1: beb54aad54880c3c7e284c50dd025c197bba03ff
sha256: 62ff6eb267a631491b2fdf08c4e3f319c882dc2cf13c6767479db46c80ad18ae
sha512: b075d5642389961995b33214f19e3eeec57c806f0a23405c1ef7835514780ebaff3643f3135269f3f17e7176516944f4eff1ae261c977e908a34a519631a0dba
ssdeep: 6144:7NKluAwuEAQY4Wr9IJgVbAnkYOpkbYxfd4QIOKA2b/qZ:70ebgVEndfCXIOK8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Elgreco xa9 2011
ProductName: Intellectuals Interruption
FileVersion: 0,233,203,127
CompanyName: Wild Tangent

ML/PE-A + Mal/Tinba-V also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004d41c61 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.514
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.1446
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Crowti.f62f0965
K7GWTrojan ( 004d41c61 )
Cybereasonmalicious.6cd8e8
SymantecRansom.Cryptodefense
ESET-NOD32Win32/Filecoder.CryptoWall.D
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Encoder.dyogpu
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentWin32.Trojan.Bp-generic.Wpav
Ad-AwareTrojan.Cripack.Gen.1
SophosML/PE-A + Mal/Tinba-V
ComodoMalware@#17a4ufdu9hmk4
BitDefenderThetaGen:NN.ZexaF.34758.pq1@aCOURycG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionGeneric trojan.i
FireEyeGeneric.mg.4ff50996cd8e8ceb
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Tpyn.sm
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Generic.ASSuf.10375
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Crowti.A
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
McAfeeGeneric .i
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
RisingTrojan.Crowti!1.A33B (CLASSIC)
YandexTrojan.Filecoder!7QGQFrXxUwA
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EEJE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove ML/PE-A + Mal/Tinba-V?

ML/PE-A + Mal/Tinba-V removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment