Malware

What is “ML/PE-A + Troj/Inject-HPE”?

Malware Removal

The ML/PE-A + Troj/Inject-HPE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Inject-HPE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine ML/PE-A + Troj/Inject-HPE?


File Info:

name: 9405E8F9808901D88D1A.mlw
path: /opt/CAPEv2/storage/binaries/856259ab256f3a5d1b10ab332d7f7f439f0e1576bbf8b3676334b8c3c72a90cf
crc32: 7C88342A
md5: 9405e8f9808901d88d1a53229b475f8a
sha1: 3c152e08c778aa129f41e1039d4c3450d765be67
sha256: 856259ab256f3a5d1b10ab332d7f7f439f0e1576bbf8b3676334b8c3c72a90cf
sha512: fd35b31182d726e9c5dcddda436cf65470b3f8625424f204f504a6d2daf015092053614fc4e911ec227a287a0bf4cf4354de23e4d790841af6fb5b389a378394
ssdeep: 12288:oew4tcUFx6AriliPVWHOkSLu1qaogT8RyZ7D1OiIot+AA27C14ppnQZH+O+TkFPG:Jw4FxyoRLIq88U31O/otIHwBQZHBFPCn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0E4E030F0E33CB7C7D68CB391B8D66456B46C4B468E6916C275BFE07AB16600BA4D1A
sha3_384: a0866bc0c15f272229296883edcf7c4e3c468da96ffb58fa2f8db314c123c2bf09097d5d2d5c8b70696bf59d8645d5f0
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-17 03:06:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: HavaianasCrypter.Exe
LegalCopyright:
OriginalFilename: HavaianasCrypter.Exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

ML/PE-A + Troj/Inject-HPE also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Razy.711362
FireEyeGeneric.mg.9405e8f9808901d8
McAfeePWS-FCRK!9405E8F98089
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.711362
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34606.Pm0@a88o7Pk
CyrenW32/MSIL_Injector.VS.gen!Eldorado
SymantecW32.Golroted!gm
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.YE
ClamAVWin.Packed.Generic-7914374-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Blackshades.dbibfy
CynetMalicious (score: 99)
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:hpBa8U8rjlDLF4k/HAMj2w)
Ad-AwareGen:Variant.Razy.711362
SophosML/PE-A + Troj/Inject-HPE
ComodoTrojWare.MSIL.Injector.YE@7jicxq
DrWebBackDoor.Blackshades.3
VIPREGen:Variant.Razy.711362
McAfee-GW-EditionPWS-FCRK!9405E8F98089
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.711362 (B)
APEXMalicious
JiangminTrojanDropper.Injector.tvy
AviraTR/Dropper.MSIL.Gen
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Razy.711362
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C3660709
Acronissuspicious
VBA32CIL.StupidPInvoker-2.Heur
ALYacGen:Variant.Razy.711362
MAXmalware (ai score=87)
MalwarebytesBackdoor.Bladabindi
PandaTrj/CI.A
IkarusWorm.Win32.Ainslot
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.25012!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.980890
AvastWin32:RATX-gen [Trj]

How to remove ML/PE-A + Troj/Inject-HPE?

ML/PE-A + Troj/Inject-HPE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment