Malware

ML/PE-A + Mal/Zbot-RJ information

Malware Removal

The ML/PE-A + Mal/Zbot-RJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Zbot-RJ virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/Zbot-RJ?


File Info:

name: CC6DBFF8DA022E468E8B.mlw
path: /opt/CAPEv2/storage/binaries/2d7a6b22cc3f46a30021be462c83b0891b57292736bd21a4696a98a17c9733e7
crc32: 2541BDE9
md5: cc6dbff8da022e468e8b2b764f7c1791
sha1: d5261c0f0532f75bd26450177d35fb0dd81909b2
sha256: 2d7a6b22cc3f46a30021be462c83b0891b57292736bd21a4696a98a17c9733e7
sha512: 042d927795d0896cc3d5e595ed95da9eb04d8c2a04c46fe4e2c50d9ee93bf1b79bf5be63504f22a0b1b35fa7d62b960b84c7827fd1e704ab48c7a3927e2debc6
ssdeep: 192:PPAc5UQopUKbNWDkBSSVCYtoQWRRgsHbtgQmQ0M8s:PPDUQsUKb8gL0QWRRgsHbABs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184A24451E6D348E8D1AA0AF10DAB71B1B6B60057D231CC991FE979B223830D605FF76E
sha3_384: 847b83fc73680ac2a33ce115e733a99b46213404153ee8a5668e7a420ce2119b0463954aaf5e8ac228d0eb845b35d357
ep_bytes: 6a00e8950b0000a320314000e8850b00
timestamp: 2014-05-19 11:25:38

Version Info:

0: [No Data]

ML/PE-A + Mal/Zbot-RJ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Ipatre.1
FireEyeGeneric.mg.cc6dbff8da022e46
McAfeeDownloader-FACS!CC6DBFF8DA02
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f8431 )
K7GWTrojan-Downloader ( 0040f8431 )
Cybereasonmalicious.8da022
BitDefenderThetaGen:NN.ZexaF.34742.auW@aeL4CMfi
CyrenW32/S-94becf64!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/TrojanDownloader.Waski.E
BaiduWin32.Trojan-Downloader.Waski.a
ClamAVWin.Malware.Upatre-7393915-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Ipatre.1
NANO-AntivirusTrojan.Win32.Zbot.cykpux
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Downloader.Win32.Upatre.we
Ad-AwareGen:Trojan.Ipatre.1
EmsisoftGen:Trojan.Ipatre.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.E@5ag7i4
DrWebTrojan.DownLoad3.33216
McAfee-GW-EditionBehavesLike.Win32.Generic.mt
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Zbot-RJ
APEXMalicious
GDataWin32.Trojan.PSE.1AH60OI
JiangminTrojanSpy.Zbot.eehr
WebrootW32.InfoStealer.Zeus
AviraTR/Dropper.Gen
ZoneAlarmTrojan-Downloader.Win32.Small.gen
MicrosoftTrojan:Win32/Waski.E!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R107311
VBA32SScope.Trojan-Downloader.1454
ALYacGen:Trojan.Ipatre.1
MAXmalware (ai score=86)
MalwarebytesTrojan.Email.FakeDoc
RisingTrojan.DL.Win32.Upatre.aaa (CLASSIC)
YandexTrojan.GenAsa!/2SMjwyI0zs
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.-Spy.Win32.Zbot.svwt
FortinetW32/Waski.E!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Mal/Zbot-RJ?

ML/PE-A + Mal/Zbot-RJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment