Malware

ML/PE-A + Troj/Konus-A removal guide

Malware Removal

The ML/PE-A + Troj/Konus-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Konus-A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:32767, 127.0.0.1:32768
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Queries information on disks, possibly for anti-virtualization
  • Sniffs keystrokes

Related domains:

api.ipify.org
time-a.nist.gov

How to determine ML/PE-A + Troj/Konus-A?


File Info:

crc32: 35D57789
md5: 1cdb3fb1f8aceed1ebe8dbf591f3d8db
name: 1CDB3FB1F8ACEED1EBE8DBF591F3D8DB.mlw
sha1: 21bd149cf8eec05f453665b888aae9b2b8e62320
sha256: 4bd4ccdaefa72f9326ba93542ddc447f6df1452a6f626a54d43c3a4c37e23968
sha512: 4df44aea1de81ee299cc0944d14da5a28290d1d3cf60691bf85a650ea12e4be73017f68bbb01466f757203e9f6d4fbdb3446a468f241a9383b35cd8f681b3021
ssdeep: 12288:rXPcLcbGfVylwG/ZDCK/ScBXo8TsyMkKMY8m7WOK98YdTTsx/SA/WegYfdNbrqn:rXh6XcBXo8TsL8Y8mWdTTySA/DrfdNb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Troj/Konus-A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00539c471 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.36652
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.25
CylanceUnsafe
ZillyaBackdoor.Konus.Win32.70
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWSpyware ( 00539c471 )
Cybereasonmalicious.1f8ace
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Kronosbot.A
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Konus.sf
BitDefenderGen:Heur.Mint.Zard.25
NANO-AntivirusTrojan.Win32.Konus.ilrxvn
MicroWorld-eScanGen:Heur.Mint.Zard.25
Ad-AwareGen:Heur.Mint.Zard.25
SophosML/PE-A + Troj/Konus-A
BitDefenderThetaAI:Packer.10C3B9AA1E
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.1cdb3fb1f8aceed1
EmsisoftGen:Heur.Mint.Zard.25 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Konus.ch
AviraHEUR/AGEN.1116604
eGambitUnsafe.AI_Score_98%
MicrosoftBackdoor:Win32/Konus.A
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Mint.Zard.25
GDataGen:Heur.Mint.Zard.25
TACHYONBanker/W32.Osiris.444928
AhnLab-V3Trojan/Win32.RL_Banker.R277924
Acronissuspicious
McAfeeGenericRXNP-XC!1CDB3FB1F8AC
MAXmalware (ai score=86)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
RisingBackdoor.Kronos!1.D39A (RDMK:cmRtazq6g3XCmBjo1aBOHFt/ERZA)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.114274721.susgen
AVGWin32:Trojan-gen

How to remove ML/PE-A + Troj/Konus-A?

ML/PE-A + Troj/Konus-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment