Malware

ML/PE-A + Troj/AutoIt-CMZ removal guide

Malware Removal

The ML/PE-A + Troj/AutoIt-CMZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/AutoIt-CMZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • Creates a copy of itself
  • Creates known Remcos mutexes
  • Creates known Remcos registry keys
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/AutoIt-CMZ?


File Info:

name: CC13F523BA9C9B7EBF91.mlw
path: /opt/CAPEv2/storage/binaries/e3d601079c756838ba11ae01ab4547ddf310ed4dcf5c8896b6663b1b70e91191
crc32: 471B0606
md5: cc13f523ba9c9b7ebf914bcda3a346db
sha1: f1cd5359df5132af556173a1ac2cdfa160eb10f3
sha256: e3d601079c756838ba11ae01ab4547ddf310ed4dcf5c8896b6663b1b70e91191
sha512: 8a48ab0c6f2e66ac4a82817f0311380cbd42ba9709c1b1e6543e10781fd50469a3aad443f1cc0c1993c81c98a3baba8bb94f7c9179efd58a321a3db064d80721
ssdeep: 24576:QAHnh+eWsN3skA4RV1Hom2KXFmIalKCc9GS5z:Hh+ZkldoPK1XalKCc9nz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118259C0273D1C036FFABA2739B6AF24156BD79354123852F13981DB9BD701B2263E663
sha3_384: b02896b4cf542f80cf76a18e65d92702f825d9f370361cdbf177c50dda212fd506a7b489a3cab42a2ba0e4a0af79220b
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-30 10:20:13

Version Info:

Translation: 0x0809 0x04b0

ML/PE-A + Troj/AutoIt-CMZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.41759
MicroWorld-eScanTrojan.GenericKD.32026646
FireEyeGeneric.mg.cc13f523ba9c9b7e
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
McAfeeTrojan-AitInject.aq
CylanceUnsafe
K7AntiVirusTrojan ( 0054f1021 )
K7GWTrojan ( 0054f1021 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaAI:Packer.9A3D7CD617
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.DZK
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.AutoIt.aop
BitDefenderTrojan.GenericKD.32026646
NANO-AntivirusTrojan.Script.Downloader.iuwddd
AvastAutoIt:Injector-JF [Trj]
TencentMalware.Win32.Gencirc.10b4d525
Ad-AwareTrojan.GenericKD.32026646
SophosML/PE-A + Troj/AutoIt-CMZ
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftTrojan.GenericKD.32026646 (B)
GDataTrojan.GenericKD.32026646
eGambitUnsafe.AI_Score_95%
AviraTR/AD.Remcos.vsbwu
Antiy-AVLTrojan/Generic.ASCommon.151
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Win-Trojan/AutoInj.Exp
VBA32Backdoor.Remcos
ALYacTrojan.GenericKD.32026646
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack.Generic
APEXMalicious
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
MaxSecureWin.MxResIcn.Heur.Gen
FortinetAutoIt/Injector.DZH!tr
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.3ba9c9

How to remove ML/PE-A + Troj/AutoIt-CMZ?

ML/PE-A + Troj/AutoIt-CMZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment