Malware

ML/PE-A + Troj/Bayrob-BV (file analysis)

Malware Removal

The ML/PE-A + Troj/Bayrob-BV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Bayrob-BV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Created a service that was not started

How to determine ML/PE-A + Troj/Bayrob-BV?


File Info:

name: 1DB57C5BDDC62E140D0C.mlw
path: /opt/CAPEv2/storage/binaries/69bbda6afe0db98184322f38093c265f871654bc6f0eadf846a5fd513dd4b7bd
crc32: 1D6AE262
md5: 1db57c5bddc62e140d0c1ba3fc35da32
sha1: 60308e852c11c88a4f20bcff462336cf76aa5b31
sha256: 69bbda6afe0db98184322f38093c265f871654bc6f0eadf846a5fd513dd4b7bd
sha512: db855b0c3e485b0f595cf8aeb99f18e47dfd23a25e24122582f3488f9c013977973e34626d8236512ed3e8b9b186611706652b04cf1152322ce0dccac590bcfb
ssdeep: 6144:2wI7q7AVcXvjvLYPSqc9TFlsrDgEY25mGLGVZ3UvR1xMfB2:2beXv0cevgRVZb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C449D44E450A3B1ED41C7F5E94ADAB6C9BE01717AB84D27C6CA2F0478B1244FB3B798
sha3_384: c552db0944b7a7f113e59c581a1b1c0f46a8adebbb6891996469a6abcf484771599fe342b5f816e6ce78964d52920741
ep_bytes: 83ec0cc70538d5450001000000e84e7c
timestamp: 2015-01-06 02:26:08

Version Info:

0: [No Data]

ML/PE-A + Troj/Bayrob-BV also known as:

BkavW32.BRBTTc.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.GZ.qGW@bSQHHQ
FireEyeGeneric.mg.1db57c5bddc62e14
CAT-QuickHealTrojanSpy.Nivdort.WR8
ALYacGen:Trojan.Heur.GZ.qGW@bSQHHQ
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004e2ee21 )
K7GWTrojan ( 004e2ee21 )
Cybereasonmalicious.bddc62
BitDefenderThetaAI:Packer.DD5332371D
CyrenW32/Nivdort.K.gen!Eldorado
SymantecTrojan.Bayrob!g10
ESET-NOD32a variant of Win32/Bayrob.CD
BaiduWin32.Trojan.Bayrob.e
TrendMicro-HouseCallTROJ_BAYROB.SMX
KasperskyHEUR:Trojan.Win32.Bayrob.gen
BitDefenderGen:Trojan.Heur.GZ.qGW@bSQHHQ
NANO-AntivirusTrojan.Win32.Dwn.ebuied
AvastWin32:Trojan-gen
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazrUIxPn0wn7hpeE1EXrTcAW)
Ad-AwareGen:Trojan.Heur.GZ.qGW@bSQHHQ
SophosML/PE-A + Troj/Bayrob-BV
DrWebTrojan.Bayrob.58
TrendMicroTROJ_BAYROB.SMX
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Trojan.Heur.GZ.qGW@bSQHHQ (B)
APEXMalicious
GDataGen:Trojan.Heur.GZ.qGW@bSQHHQ
JiangminTrojan.Bayrob.nuc
AviraHEUR/AGEN.1118567
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.181B479
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R178732
Acronissuspicious
McAfeeTrojan-FIIE!1DB57C5BDDC6
TACHYONTrojan/W32.Bayrob.265728.B
VBA32BScope.Trojan.Diple
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!ybOLeOIGTA0
IkarusTrojan.Win32.Bayrob
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.BR!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Troj/Bayrob-BV?

ML/PE-A + Troj/Bayrob-BV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment