Malware

Should I remove “ML/PE-A + Troj/Agent-BGQS”?

Malware Removal

The ML/PE-A + Troj/Agent-BGQS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-BGQS virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

cutit.org

How to determine ML/PE-A + Troj/Agent-BGQS?


File Info:

crc32: 9CB5F694
md5: ea06503d7aea40f3fbca121191303570
name: EA06503D7AEA40F3FBCA121191303570.mlw
sha1: 0709e56c1ba0a3216dd7e417f712c9d2e9c5c942
sha256: 8cc73c8488f06d55e5e0dd74feaf30280a5684bdaf1608695c1ef0c1d7d25ebe
sha512: 571b385d29dd06c9a980070f748e209205e69f122f40d641ee0d79084bcf1eae619b53c58909e69b840ea436b7a77de6d8330ab8e65e8fb562be60d3def98689
ssdeep: 12288:U8F84iI2jD9HY3BAqFYwt4q0qhW20zp5QAetmuHBsJc:xF78xcAqFYwJ0Vzp5KAur
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

ML/PE-A + Troj/Agent-BGQS also known as:

K7AntiVirusTrojan ( 0057984e1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
ALYacGen:Variant.Razy.576052
CylanceUnsafe
ZillyaTrojan.Injector.Win32.973830
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Injector.1c0ab330
K7GWTrojan ( 0057984e1 )
Cybereasonmalicious.d7aea4
CyrenW32/Kryptik.DND.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EBQH
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.576052
NANO-AntivirusTrojan.Win32.Razy.ipqwlq
MicroWorld-eScanGen:Variant.Razy.576052
TencentWin32.Trojan.Generic.Ajbi
Ad-AwareGen:Variant.Razy.576052
SophosML/PE-A + Troj/Agent-BGQS
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1111440
BitDefenderThetaGen:NN.ZexaF.34236.DmW@au7DkUl
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03BC0RF621
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
FireEyeGeneric.mg.ea06503d7aea40f3
EmsisoftGen:Variant.Razy.576052 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gzjqj
AviraHEUR/AGEN.1111440
eGambitUnsafe.AI_Score_86%
Antiy-AVLTrojan/Generic.ASBOL.C687
MicrosoftTrojan:Win32/Ditertag.A
GDataGen:Variant.Razy.576052
AhnLab-V3Malware/Gen.RL_Reputation.R368477
McAfeeGenericRXAA-FA!EA06503D7AEA
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0RF621
RisingTrojan.Kryptik!1.D238 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.BGQS!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove ML/PE-A + Troj/Agent-BGQS?

ML/PE-A + Troj/Agent-BGQS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment