Malware

About “ML/PE-A + Troj/Agent-YBF” infection

Malware Removal

The ML/PE-A + Troj/Agent-YBF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-YBF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Telugu
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Agent-YBF?


File Info:

crc32: 7A1417D4
md5: db39a3fb1fad2d1af413ba626615b6ce
name: DB39A3FB1FAD2D1AF413BA626615B6CE.mlw
sha1: b53021b0a6e70b87b3636e9bbe23066918ba78ea
sha256: 6c9a46fdb539e37eb6a7303ee433ee0e46ddcb78565966c06ff017ef95fe26fc
sha512: 9a4758cd3d6263d40c01372420b310a828cef6b4f3dbc6962404337d21c03e780faf192dcb3aff9f58428e1952ca98c88d8249855c6a9c32b7dd437124a6edeb
ssdeep: 3072:XXOTk9hdWv1X8FV5LQz4fQoyDqAQQa3wMYcsHWorhp9JpS9f+MK04J+w6GcDzPS:Oo9hdW94V5sWGnOzYko1p9/k816Gyzq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: a
FileVersion: 1.00
CompanyName: M dhfgfdghgsdfdhd gs
LegalTrademarks: tazzina caffxe8 CALDA
ProductName: Lambretta special
ProductVersion: 1.00
FileDescription: Inside your a.b.c.
OriginalFilename: a.exe

ML/PE-A + Troj/Agent-YBF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0029a43a1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.78544
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Spyware.61e8a936
K7GWSpyware ( 0029a43a1 )
Cybereasonmalicious.b1fad2
SymantecTrojan Horse
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
AvastWin32:Spyware-gen [Spy]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Panda.dxcnqd
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Generic.Wrqf
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Troj/Agent-YBF
ComodoMalware@#17x8lttvvobz6
BitDefenderThetaAI:Packer.358C71FB21
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_AGENT_BK08478B.TOMC
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
FireEyeGeneric.mg.db39a3fb1fad2d1a
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.foc
WebrootW32.Malware.Gen
AviraTR/Dropper.VB.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.5FF72
MicrosoftPWS:Win32/Zbot
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Cerber.1
TACHYONTrojan-Spy/W32.VB-ZBot.328704.B
AhnLab-V3Spyware/Win32.Zbot.R39112
Acronissuspicious
McAfeePWS-Zbot.gen.oj
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
PandaGeneric Malware
TrendMicro-HouseCallTSPY_AGENT_BK08478B.TOMC
YandexTrojan.GenAsa!fDTJfTN0ahw
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dorkbot.BAA!tr
AVGWin32:Spyware-gen [Spy]
Paloaltogeneric.ml

How to remove ML/PE-A + Troj/Agent-YBF?

ML/PE-A + Troj/Agent-YBF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment