Malware

How to remove “ML/PE-A + Troj/Agent-BDKO”?

Malware Removal

The ML/PE-A + Troj/Agent-BDKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-BDKO virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

www.rmagent.biz
al-sharqgroup.com

How to determine ML/PE-A + Troj/Agent-BDKO?


File Info:

crc32: 101D8043
md5: 4ed55d3cbfb62db9c28d47d91adb0841
name: 4ED55D3CBFB62DB9C28D47D91ADB0841.mlw
sha1: 1871559b8c18efc57428e329dfba49611851ab7e
sha256: b3f5b8a028e3f6f81c98a7ef5f987c75df866875f5f76f8e771aff395a6597d2
sha512: e8283d52052e6192c90f6eb7d482899e4540e43c05fdc370c3f0a006787698308442a659b7f1a805af9e984692eca3d2cf6ff0c30fa80cc5bb8c903d2ce465c4
ssdeep: 24576:AAHnh+eWsN3skA4RV1Hom2KXMmHa2nMviVT5B:3h+ZkldoPK8Ya2nwivB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

ML/PE-A + Troj/Agent-BDKO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader28.36060
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AutoIt.Injector.A5
ALYacAIT:Trojan.Nymeria.3920
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000111 )
Cybereasonmalicious.cbfb62
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecAUT.Heuristic!gen1
ESET-NOD32a variant of Win32/Packed.AutoIt.PC
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
ClamAVWin.Malware.Autoit-6989454-0
KasperskyTrojan.Script.Obit.gen
BitDefenderAIT:Trojan.Nymeria.3920
MicroWorld-eScanAIT:Trojan.Nymeria.3920
TencentMalware.Win32.Gencirc.10b0d179
Ad-AwareAIT:Trojan.Nymeria.3920
SophosML/PE-A + Troj/Agent-BDKO
BitDefenderThetaAI:Packer.F34CB91817
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.dh
FireEyeGeneric.mg.4ed55d3cbfb62db9
EmsisoftAIT:Trojan.Nymeria.3920 (B)
AviraDR/AutoIt.Gen8
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASCommon.151
MicrosoftVirTool:Win32/AutInject.DE!bit
ArcabitAIT:Trojan.Nymeria.DF50
GDataAIT:Trojan.Nymeria.3920 (2x)
AhnLab-V3Win-Trojan/Autoinj02.Exp
McAfeeAutoIt/Injector.ax
MAXmalware (ai score=81)
VBA32Backdoor.Remcos
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaTrj/Genetic.gen
RisingTrojan.Injector/Autoit!1.BB8F (CLASSIC)
IkarusTrojan.Autoit
MaxSecureWin.MxResIcn.Heur.Gen
FortinetAutoIt/Injector.EKY!tr
AVGAutoIt:Injector-JF [Trj]

How to remove ML/PE-A + Troj/Agent-BDKO?

ML/PE-A + Troj/Agent-BDKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment