Malware

ML/PE-A + Mal/VB-CMXA removal

Malware Removal

The ML/PE-A + Mal/VB-CMXA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/VB-CMXA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine ML/PE-A + Mal/VB-CMXA?


File Info:

crc32: E12A0625
md5: 5540db85e12776c19aa7b9f9872a290e
name: 5540DB85E12776C19AA7B9F9872A290E.mlw
sha1: 50b829e5c4194e28455242667e2ae89aeef7b99e
sha256: 23748e2a5ff0e8325cba4a6d665282253b81ef15da753a16ece776e949c33521
sha512: 65d4e54e5503e443832d6277238fc8f507a7092ffc4d22c42c857848aa7a00f37b8c4b000c185872f6251b8cf5ab97d621bf9bfc464f0760fcc04c67d6860e80
ssdeep: 768:H7xDgR0iXvbPqdOtzDnhiL6LasGjJxBg/PnHApfStSl3N92Nk+Cke/LpA2ETjRy:bx8qazDnh1atj4ngeSl3Nh+CM2EZvek
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: RvISB
InternalName: Stub
FileVersion: 1.00
CompanyName: CztLIgBagcorF
Comments: dmwrUk
ProductName: DivuKNQIh
ProductVersion: 1.00
FileDescription: pbCZlzhyko
OriginalFilename: Stub.exe

ML/PE-A + Mal/VB-CMXA also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.8
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericVMF.S21462207
ALYacGen:Heur.ManBat.1
CylanceUnsafe
ZillyaBackdoor.Bifrose.Win32.53139
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaVirTool:Win32/VBInject.fc890873
Cybereasonmalicious.5e1277
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Bifrose
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Trojan.6094776-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.VB.ecckqy
MicroWorld-eScanGen:Heur.ManBat.1
TencentWin32.Trojan.Crypt.Suds
Ad-AwareGen:Heur.ManBat.1
SophosML/PE-A + Mal/VB-CMXA
ComodoTrojWare.Win32.SGen.A@4ll7lp
BitDefenderThetaAI:Packer.628E60161F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DG821
McAfee-GW-EditionBehavesLike.Win32.Trojan.qc
FireEyeGeneric.mg.5540db85e12776c1
EmsisoftGen:Heur.ManBat.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.omxa
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.183A3B4
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.ManBat.1
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp[Cont]
GDataGen:Heur.ManBat.1
McAfeeArtemis!5540DB85E127
MAXmalware (ai score=100)
VBA32Malware-Cryptor.VB.gen.7
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DG821
YandexTrojan.Bifrose!jsWMAnQEbaQ
IkarusTrojan.SuspectCRC
FortinetW32/Refroso.DZP!tr
AVGFileRepMetagen [Malware]

How to remove ML/PE-A + Mal/VB-CMXA?

ML/PE-A + Mal/VB-CMXA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment