Malware

What is “ML/PE-A + Mal/VBDrop-D”?

Malware Removal

The ML/PE-A + Mal/VBDrop-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/VBDrop-D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine ML/PE-A + Mal/VBDrop-D?


File Info:

name: 97A4B851479B6EE2018D.mlw
path: /opt/CAPEv2/storage/binaries/c86833d50f76db3002f90d36f0237efc38a8717ad4c78ad898cbbdef011c135d
crc32: 52237ACA
md5: 97a4b851479b6ee2018d1ec324c9aad6
sha1: 468f6c226bee7be7801bf35feccbce9d8b6c09e3
sha256: c86833d50f76db3002f90d36f0237efc38a8717ad4c78ad898cbbdef011c135d
sha512: 829e72b022016102b778ba09a996945f3ac58504b10fd9acade677b765036135675df680a00c86c26fd4690685a2db74d846abd053bd62cba57b5477b7ba5782
ssdeep: 6144:VGUeEW75rfLia2wVHSFgxphh/7nrn6PMkFOx9CIHiettQI:VLW75rfLRXVyFgDh/PJKOxOI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CDA45A127AA0D036F6B60632CE6AC7A6F6E3ACB04C2145C733A43E6DED359436525F74
sha3_384: d50e17b8b7d436d6413a7dccb1ea26443b65affa4df9fdf9b634b50bb4dae8c64f2f680727140bb6ec6121af73e8c7d0
ep_bytes: 68bc764000e8f0ffffff000000000000
timestamp: 2007-07-23 13:18:13

Version Info:

0: [No Data]

ML/PE-A + Mal/VBDrop-D also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Trojan.VBGeneric-6735767-0
FireEyeGeneric.mg.97a4b851479b6ee2
CAT-QuickHealTrojan.Comisproc.AZ3
McAfeeGenericRXBZ-FU!97A4B851479B
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577b961 )
K7GWTrojan ( 00577b961 )
Cybereasonmalicious.1479b6
BaiduWin32.Trojan.VB.je
CyrenW32/Risk.FJRN-7411
SymantecTrojan.Gen.MBT
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.VB.fer
BitDefenderGen:Variant.Razy.980715
NANO-AntivirusTrojan.Win32.VB.epyowu
MicroWorld-eScanGen:Variant.Razy.980715
AvastWin32:Dh-A [Heur]
TencentTrojan.Win32.Agent.bc
Ad-AwareGen:Variant.Razy.980715
SophosML/PE-A + Mal/VBDrop-D
ComodoWorm.Win32.Agent.VBC@4×4502
DrWebTrojan.Siggen3.12086
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
EmsisoftGen:Variant.Razy.980715 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.980715
JiangminWorm.VB.olf
MaxSecureWorm.Vb.fer
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASBOL.9FD7
ArcabitTrojan.Razy.DEF6EB
ViRobotWorm.Win32.A.VB.195072.A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Worm/Win32.RL_VB.R364377
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34062.CuZ@a05NVko
ALYacGen:Variant.Razy.980715
VBA32Worm.VB
MalwarebytesMalware.AI.536282046
YandexTrojan.VBGent.Gen.1634
IkarusWorm.Win32.VB
FortinetW32/CoinMiner.F
WebrootW32.Trojan.Gen
AVGWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove ML/PE-A + Mal/VBDrop-D?

ML/PE-A + Mal/VBDrop-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment