Malware

What is “ML/PE-A + Troj/Agent-QQK”?

Malware Removal

The ML/PE-A + Troj/Agent-QQK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-QQK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine ML/PE-A + Troj/Agent-QQK?


File Info:

name: 61D1A356045FD0D14759.mlw
path: /opt/CAPEv2/storage/binaries/fdf641bcc5fa3a314624f527a1d07f3a8d4c359850b6fef51d0bc02405c0e79c
crc32: A6696E7E
md5: 61d1a356045fd0d14759ffe3c65cf550
sha1: daed7db5b3707465c81254e3a1977d2255252aad
sha256: fdf641bcc5fa3a314624f527a1d07f3a8d4c359850b6fef51d0bc02405c0e79c
sha512: fd5fe02a91870d0a10261feac377f1e899a63ba05a221b4b62db572a92e75d171cd9b1df305f7e9b5d6e09db78973a2fc3dc1d8d0b008903fb80bc8ab5032b37
ssdeep: 3072:x/rrLSljKnwwHI3+JKC7J8to5GABfmDiAOMpcggYg8UTz/Zd4Od7Px8nf:0ljKuuFJ8to5GOa3gYg8ehya7Px8f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109F3022B37B615B5D8F48C387CA2669D8CFC75644CD282913B86BD4DAD39304291DFB2
sha3_384: fe9a2cfde5adbff002180c426828f534b7fabb8b97617f1ed5bdd32d8d4cadd5c9b41523b80015825a6447254ac0f34d
ep_bytes: 41558bec83c4bc13d941f7d842bf98e6
timestamp: 2005-12-15 10:46:16

Version Info:

CompanyName: Pcnwpfjkut Oxrndlov
FileDescription: Pcnwpfjkut Vhjgjx Ansncs
FileVersion: 116, 9, 27, 121
InternalName: Pcnwpfjkut
LegalCopyright: Copyright © Pcnwpfjkut Oxrndlov 2000-2009
OriginalFilename: Pcnwpfjkut.exe
ProductName: Pcnwpfjkut Vhjgjx Ansncs
ProductVersion: 33, 122, 97, 11
Translation: 0x0409 0x04e4

ML/PE-A + Troj/Agent-QQK also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.655
MicroWorld-eScanGen:Variant.Ser.Razy.7890
FireEyeGeneric.mg.61d1a356045fd0d1
CAT-QuickHealWorm.SlenfBot.Gen
McAfeeArtemis!61D1A356045F
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 004eea4d1 )
AlibabaTrojanPSW:Win32/Kryptik.fece7e97
K7GWTrojan ( 004eea4d1 )
Cybereasonmalicious.6045fd
BitDefenderThetaGen:NN.ZexaF.34212.kq1@auPPB0nc
VirITTrojan.Win32.Panda.ZF
SymantecW32.Qakbot!gen5
ESET-NOD32a variant of Win32/Kryptik.MHV
TrendMicro-HouseCallBKDR_QAKBOT.SMG
AvastWin32:MalOb-FS [Cryp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.7890
NANO-AntivirusTrojan.Win32.Panda.wchwd
SUPERAntiSpywareTrojan.Agent/Gen-Falprod[Cont]
TencentMalware.Win32.Gencirc.114bf56e
Ad-AwareGen:Variant.Ser.Razy.7890
EmsisoftGen:Variant.Ser.Razy.7890 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
VIPRETrojan.Win32.Kryptik.mcf (v)
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Troj/Agent-QQK
Paloaltogeneric.ml
GDataGen:Variant.Ser.Razy.7890
JiangminTrojanSpy.Zbot.awcr
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Ser.Razy.D1ED2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!ZA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Qakbot.C760537
ALYacGen:Variant.Ser.Razy.7890
MAXmalware (ai score=99)
VBA32Trojan.Zeus.EA.0999
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Agent!dOWay0iFFjo
SentinelOneStatic AI – Malicious PE
eGambitGeneric.PSW
FortinetW32/Kryptik.NAS!tr
AVGWin32:MalOb-FS [Cryp]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove ML/PE-A + Troj/Agent-QQK?

ML/PE-A + Troj/Agent-QQK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment