Malware

ML/PE-A + Troj/HkMain-AZ removal guide

Malware Removal

The ML/PE-A + Troj/HkMain-AZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/HkMain-AZ virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Saudi Arabia)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/HkMain-AZ?


File Info:

name: 0B460659123F8053C55A.mlw
path: /opt/CAPEv2/storage/binaries/8b40f33246eecd3d1f9edd1a45f6179577f9f66000d6f6824b9f8d86782ed51c
crc32: 00A745B6
md5: 0b460659123f8053c55ab2000419987f
sha1: 78f1ee8debc8ad80c189a28f27437bcfdd210411
sha256: 8b40f33246eecd3d1f9edd1a45f6179577f9f66000d6f6824b9f8d86782ed51c
sha512: b252e3c4bde716fd4f9c113de1d79644d9fb0026a7ad52e145256d8e2fb8268ee78c2b359aa35eea8bc7b6fec627ba98d0c0ae202eb94976db5931e89262c84a
ssdeep: 384:LQEgwsEoVnWCqO5rMhXCYpL6QNxfGya1IvmF7K:/gwEnWEZMhyINGyGI+K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6F251318ADC08B5F3B7CE3E15B142935432BC612B268ACF94A471B80473EB5DBAD649
sha3_384: cd77e047d3c7c35109dc871947e4ca5e31d5feb115f46b18939afca1816af74b0024b7e6e852eac505f6e2522edfc1f8
ep_bytes: 57565351e857feffffc3cccccccccccc
timestamp: 1973-02-28 09:38:41

Version Info:

CompanyName: NALIK
FileDescription: NALIK company
FileVersion: Version 2.1.1
InternalName: NALIK
LegalCopyright: Copyright by NALIK
OriginalFilename: NALIK
Translation: 0x040a 0x04e3

ML/PE-A + Troj/HkMain-AZ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Upatre.87
MicroWorld-eScanGen:Variant.Daytre.30
FireEyeGeneric.mg.0b460659123f8053
CAT-QuickHealTrojan.GenericPMF.S24187025
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.70045
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.9123f8
BitDefenderThetaGen:NN.ZexaF.34062.cq1@aSdOddpO
CyrenW32/Waski.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
TrendMicro-HouseCallTROJ_UPATRE.SMBG
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.efj
BitDefenderGen:Variant.Daytre.30
NANO-AntivirusTrojan.Win32.MlwGen.dewlww
AvastWin32:Agent-AULS [Trj]
TencentMalware.Win32.Gencirc.10cf8eb7
Ad-AwareGen:Variant.Daytre.30
SophosML/PE-A + Troj/HkMain-AZ
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan-Downloader.Win32.Cutwail.bza (v)
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nt
EmsisoftGen:Variant.Daytre.30 (B)
IkarusPacker.Win32.Krap
GDataGen:Variant.Daytre.30
JiangminTrojanDropper.Dapato.pdf
AviraHEUR/AGEN.1135285
Antiy-AVLTrojan/Generic.ASMalwS.BE749D
ViRobotTrojan.Win32.U.Downloader.22528
MicrosoftTrojanDownloader:Win32/Upatre.AA
TACHYONDownloader/W32.Agent.37444
AhnLab-V3Downloader/Win.Upatre.C4704608
Acronissuspicious
McAfeeDownloader-FAGV!0B460659123F
MAXmalware (ai score=80)
VBA32Hoax.Cryptodef
MalwarebytesTrojan.Upatre.Generic
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:NwCuv19Rr61JRzn4g57Hzw)
YandexTrojan.DL.Upatre!gjWar6A3s3o
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Troj/HkMain-AZ?

ML/PE-A + Troj/HkMain-AZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment