Malware

About “ML/PE-A + Troj/AutoIt-CKV” infection

Malware Removal

The ML/PE-A + Troj/AutoIt-CKV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/AutoIt-CKV virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine ML/PE-A + Troj/AutoIt-CKV?


File Info:

name: B82116278172F28041B8.mlw
path: /opt/CAPEv2/storage/binaries/9142fe6dc3a8ea24c81892fc0b8c8bc7f7280e6e27ad3e344a04fb2409f60b79
crc32: 782C5E01
md5: b82116278172f28041b84e528f4e7df0
sha1: d75e2d1291d7578969507cb0a455ebbe03ece0c8
sha256: 9142fe6dc3a8ea24c81892fc0b8c8bc7f7280e6e27ad3e344a04fb2409f60b79
sha512: 410d9c38190f81f293dbf5ed060324ada103f8a8937c17331a418e67ef91e5cc4f2e3730a04a8a0313dc1483e1113649ac7cc9086ab16145a5554889d4d59db4
ssdeep: 24576:iAHnh+eWsN3skA4RV1Hom2KXcGtczA6osgiHtVkNkF:lh+ZkldoPKs6czboh6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C555AEC2AF90F035FFAA5E734B69B10612F93D7D1423D01E5698FC79BA315A1122DA23
sha3_384: 55361c4b8b4a5628910211f206de771f52c4222b5c26a6ea2a9abf0423b58b68515f1fcd5525a6152f4ecc7de19ecbc6
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-02 22:29:34

Version Info:

Translation: 0x0809 0x04b0

ML/PE-A + Troj/AutoIt-CKV also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.AutoIT.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.12
ClamAVWin.Malware.Autoit-6970459-1
FireEyeGeneric.mg.b82116278172f280
CAT-QuickHealTrojan.AutoIt.Strictor.ZZ
ALYacGen:Trojan.Heur.AutoIT.12
VIPREGen:Trojan.Heur.AutoIT.12
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AitInject.f1fe6a9a
K7GWTrojan ( 0055dc781 )
K7AntiVirusTrojan ( 0055dc781 )
SymantecPacked.Generic.548
tehtrisGeneric.Malware
ESET-NOD32Win32/Packed.Autoit.NBB suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Autoit.fnm
BitDefenderGen:Trojan.Heur.AutoIT.12
NANO-AntivirusTrojan.Win32.AutoIT.gwbsfy
SUPERAntiSpywareTrojan.Agent/Gen-Loki
AvastAutoIt:Injector-JF [Trj]
TencentMalware.Win32.Gencirc.10b300d5
Ad-AwareGen:Trojan.Heur.AutoIT.12
SophosML/PE-A + Troj/AutoIt-CKV
ComodoMalware@#1s8h3hfr8w0nb
DrWebTrojan.PWS.Siggen2.13593
TrendMicroBackdoor.Autoit.NANOCORE.SMAT.hp
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.AutoIT.12 (B)
GDataGen:Trojan.Heur.AutoIT.12
AviraDR/AutoIt.Gen8
Antiy-AVLGrayWare/Autoit.ShellCode.a
ArcabitTrojan.Heur.AutoIT.12
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
McAfeeArtemis!B82116278172
MAXmalware (ai score=96)
VBA32Trojan-Downloader.Autoit.gen
TrendMicro-HouseCallBackdoor.Autoit.NANOCORE.SMAT.hp
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
IkarusTrojan.Autoit
FortinetAutoIt/Injector.DYD!tr
BitDefenderThetaAI:Packer.39DE3CF819
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.78172f
PandaTrj/Genetic.gen

How to remove ML/PE-A + Troj/AutoIt-CKV?

ML/PE-A + Troj/AutoIt-CKV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment