Malware

About “ML/PE-A + Troj/Agent-ADIT” infection

Malware Removal

The ML/PE-A + Troj/Agent-ADIT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-ADIT virus can do?

  • Unconventionial language used in binary resources: Russian
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Agent-ADIT?


File Info:

name: 91D2AA1FB2805198678C.mlw
path: /opt/CAPEv2/storage/binaries/0edead26b4ceaa251b682ce846e6ce5b1bea60209f53ed4a590985816fab2cd7
crc32: 48CDA8BC
md5: 91d2aa1fb2805198678cd346f7dde92f
sha1: 49304bcefbb7d3c2844eded3e32c714ed3dcccc1
sha256: 0edead26b4ceaa251b682ce846e6ce5b1bea60209f53ed4a590985816fab2cd7
sha512: e570883c705652551ef33cdf01ac5ef60ab0a52872d8d24a074a1f502be3f0e015c53166b7eb15c6624e8e61e4160f7d5e858c0662758c3b01f4fbf8a0ef3dc8
ssdeep: 384:yOybKp5ntkR9sJr7nyodGhpxMR5QYKZseH5SAm:yO2Kp5Esl7yD7QDKVO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DB231B0F582BD73D016453071BAF588092E2E123B9AA51D3EAAF36C47F670134C5E6E
sha3_384: d3d1fc17287044f4be6564b524cbad01c2ab5d0412e066f357cb05f0eef5492fab048e76ad13518b0aa5fe366b4e173b
ep_bytes: 558bec83ec645356575064a130000000
timestamp: 2013-08-27 09:48:40

Version Info:

0: [No Data]

ML/PE-A + Troj/Agent-ADIT also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Spy.Zbot.FHF
FireEyeGeneric.mg.91d2aa1fb2805198
CAT-QuickHealTrojanDownloader.Upatre.A3
ALYacTrojan.Spy.Zbot.FHF
CylanceUnsafe
ZillyaDownloader.Small.Win32.71340
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fb2805
BitDefenderThetaGen:NN.ZexaF.34182.bmX@aa@3sMhk
VirITTrojan.Win32.Generic.CHGU
CyrenW32/Trojan.LLDF-4766
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Small.PRL
TrendMicro-HouseCallTROJ_UPATRE.SM
ClamAVWin.Trojan.Zbot-59484
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Spy.Zbot.FHF
NANO-AntivirusTrojan.Win32.DownLoad3.cjbusg
AvastWin32:Zbot-RUD [Trj]
TencentMalware.Win32.Gencirc.10b9db37
SophosML/PE-A + Troj/Agent-ADIT
ComodoTrojWare.Win32.TrojanDownloader.Tiny.NIU@7ajbk5
BaiduWin32.Trojan-Downloader.Small.by
VIPRETrojan.Win32.Kryptik.bixx (v)
TrendMicroTROJ_UPATRE.SM
EmsisoftTrojan.Spy.Zbot.FHF (B)
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojan/Generic.bakcv
AviraTR/AD.Yarwi.amqdm
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.3F86FD
MicrosoftTrojanDownloader:Win32/Upatre.A
GDataTrojan.Spy.Zbot.FHF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.C184755
McAfeePWSZbot-FFC!91D2AA1FB280
VBA32BScope.Trojan.Bublik
APEXMalicious
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazpdReg2xPK8mjKUSsnr+l1h)
YandexTrojan.GenAsa!nhuQdixS3/4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Tiny.NIV!tr.dldr
AVGWin32:Zbot-RUD [Trj]
PandaTrj/Zbot.M
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Troj/Agent-ADIT?

ML/PE-A + Troj/Agent-ADIT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment