What is “ML/PE-A + Troj/Agent-BGMO”?

Malware Removal

The ML/PE-A + Troj/Agent-BGMO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What ML/PE-A + Troj/Agent-BGMO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (16 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

www.freeav.com
www.bing.com
apps.identrust.com
www.antispyware.com
ocsp.pki.goog
img1.wsimg.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org
ocsp.starfieldtech.com
crl.starfieldtech.com

How to determine ML/PE-A + Troj/Agent-BGMO?


File Info:

crc32: D6582BAB
md5: 9a75b75401a701b7cdc27c63920cad3e
name: 9A75B75401A701B7CDC27C63920CAD3E.mlw
sha1: a077965ab66cf72dd36dbf24d3db317fec8bf71a
sha256: cfb203a818ed3805b157ffd86ab46e87379e4f565ae8e255dcce07e941e0223b
sha512: 57ea9451cb113a5c68a38c6e90292f885094e144c8fe5b01453bfb38e5b761e151186060e32012e0ff12c3e5f3edd67f6de294305914733c619f003aaae8c976
ssdeep: 24576:ieb8Fpa6aHX7dGP5Gv3Ooc8UHkC2ekUeb8Fpa6aHX7dGP5Gv3Ooc8UHkC2ekx:AxapGsaxapGs9
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

ML/PE-A + Troj/Agent-BGMO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051918e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Click3.29339
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericIH.S20203434
ALYacTrojan.GenericKD.45798479
CylanceUnsafe
ZillyaDropper.Agent.Win32.443301
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.401a70
CyrenW32/Agent.CGR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.SNX
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Fileinfector-9832954-0
KasperskyHEUR:Trojan-Dropper.Win32.Agent.vho
BitDefenderTrojan.GenericKD.45798479
NANO-AntivirusTrojan.Win32.Clicker.dapdse
MicroWorld-eScanTrojan.GenericKD.45798479
TencentMalware.Win32.Gencirc.11bb25d9
Ad-AwareTrojan.GenericKD.45798479
SophosML/PE-A + Troj/Agent-BGMO
BitDefenderThetaAI:Packer.12EE1ED61E
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.9a75b75401a701b7
EmsisoftTrojan.GenericKD.45798479 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.cae
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.23431
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2BAD44F
GDataTrojan.GenericKD.45798479
AhnLab-V3Malware/Gen.RL_Reputation.R365233
McAfeeGenericRXAA-AA!9A75B75401A7
MAXmalware (ai score=82)
VBA32Trojan.Click
MalwarebytesTrojan.Clicker
RisingTrojan.Kryptik!1.D30B (CLASSIC)
YandexTrojan.Agent!sDgRjKyvUDs
IkarusTrojan.Win32.Genome
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.E970!tr
AVGWin32:Trojan-gen

How to remove ML/PE-A + Troj/Agent-BGMO?

ML/PE-A + Troj/Agent-BGMO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment