Malware

ML/PE-A + Troj/Agent-AJCY removal instruction

Malware Removal

The ML/PE-A + Troj/Agent-AJCY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-AJCY virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine ML/PE-A + Troj/Agent-AJCY?


File Info:

name: 9C7FE4CABA5B679D9EE5.mlw
path: /opt/CAPEv2/storage/binaries/c0c98d4394043fe841c5392777e23a4a1e4eebb334dd50aa44d747d7d9ad4894
crc32: 2F919351
md5: 9c7fe4caba5b679d9ee56df316f4c953
sha1: 62c455373df08e1902416234bbb1153ce5291d39
sha256: c0c98d4394043fe841c5392777e23a4a1e4eebb334dd50aa44d747d7d9ad4894
sha512: 4204f979d2ba364095f8646be2480334d2212f1a629d1d52008f620a7ff473d2c236bd26653f7a334cdb2c4a70aef9b85f7661de8a048a44d5ac7f6b076572f4
ssdeep: 192:yuJ5vKe3A1u3X0Aaolso1Q/9TukoRxj/Qhw/9LtHwXJVRudnGnjQGny/:yuJ5ie3Aw3Xflu/9akoLjJ9LtHwLR+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9A284788BD60AB8F332CE7249B2825B7534BD216762069F4150BA714C33DF29F3E995
sha3_384: ac67c9a9ca4d7457acc77aedacdd3c4d07d246eb158ae4347a996b5f73cc91ee82d14a1a04e515794a0b7d96ca88969b
ep_bytes: 55505050e827f2ffff5dc3ff6a8b6acc
timestamp: 2071-10-05 01:41:45

Version Info:

CompanyName: FASTER
FileDescription: FASTER company
FileVersion: Version 0.1.8
InternalName: FASTER
LegalCopyright: Copyright by FASTER Inc.
OriginalFilename: FASTER
Translation: 0x0416 0x04e4

ML/PE-A + Troj/Agent-AJCY also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Upatre.100
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.9c7fe4caba5b679d
CAT-QuickHealTrojanDwnldr.Upatre.AA4
ALYacTrojan.Ppatre.Gen.1
MalwarebytesTrojan.Downloader
ZillyaDownloader.Upatre.Win32.54397
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.aba5b6
ArcabitTrojan.Ppatre.Gen.1
BitDefenderThetaGen:NN.ZexaF.34182.bq1@aijOHMnO
VirITTrojan.Win32.Generic.DCC
CyrenW32/A-10a39d23!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.CMHS
TrendMicro-HouseCallTROJ_UPATRE.SM37
AvastWin32:Agent-AULS [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.elp
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Kryptik.dgtmdt
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareTrojan.Ppatre.Gen.1
SophosML/PE-A + Troj/Agent-AJCY
ComodoTrojWare.Win32.TrojanDownloader.Waski.EB@5j320p
BaiduWin32.Trojan-Downloader.Waski.a
VIPRELooksLike.Win32.Upatre.a (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
EmsisoftTrojan.Ppatre.Gen.1 (B)
JiangminTrojanDownloader.Upatre.gv
eGambitUnsafe.AI_Score_95%
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.C78D69
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
GDataWin32.Trojan-Downloader.Upatre.BK
AhnLab-V3Trojan/Win32.Downloader.R120631
Acronissuspicious
McAfeeDownloader-FSH
VBA32TrojanDownloader.Upatre
APEXMalicious
RisingDownloader.Waski!1.A489 (RDMK:cmRtazqx9UB4beKIdrUHXyyJBOjI)
YandexTrojan.GenAsa!zbyKuNjPV4k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove ML/PE-A + Troj/Agent-AJCY?

ML/PE-A + Troj/Agent-AJCY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment