Categories: Malware

ML/PE-A + Troj/Lyposit-C (file analysis)

The ML/PE-A + Troj/Lyposit-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Lyposit-C virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Lyposit-C?


File Info:

crc32: FC1C5BC0md5: c1c42bf03d3f0867624f8b89fc57d578name: C1C42BF03D3F0867624F8B89FC57D578.mlwsha1: 7277b1ec5bcbb5e45cccfc0e5674501ae4a04644sha256: 3ba78bb246de56e0933eacfa5774984775935bb6ed8c2c579bd6e806c0ef0e00sha512: c6330e3061f47758a6cec62c49e7a4654787859f7d39afe3e54512771023e838ccb0d39d173384d9ae48261587c021b4794a53fee0ccdce14d7a0f5b059c1592ssdeep: 12288:GFBwPIhicug08fQ9odJKyMzFltRtFIxHL:GFBYovug7Jdwltirtype: MS-DOS executable

Version Info:

0: [No Data]

ML/PE-A + Troj/Lyposit-C also known as:

Bkav W32.FamVT.RsLpTTc.Worm
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fugrafa.1845
FireEye Generic.mg.c1c42bf03d3f0867
ALYac Gen:Variant.Fugrafa.1845
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 004cbc7e1 )
BitDefender Gen:Variant.Fugrafa.1845
K7GW Trojan ( 004cbc7e1 )
Cybereason malicious.03d3f0
BitDefenderTheta Gen:NN.ZexaF.34590.EiZ@aCKlxC
Cyren W32/SuspPack.AB.gen!Eldorado
Symantec SMG.Heur!gen
ESET-NOD32 a variant of Win32/Lyposit.A
APEX Malicious
Avast Win32:Trojan-gen
Kaspersky HEUR:Trojan.Win32.Generic
NANO-Antivirus Trojan.Win32.Clicker.efvwpu
AegisLab Trojan.Win32.Generic.lak4
Tencent Malware.Win32.Gencirc.10b0788b
Ad-Aware Gen:Variant.Fugrafa.1845
Sophos ML/PE-A + Troj/Lyposit-C
Comodo TrojWare.Win32.Lyposit.C@6tos6b
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.Click2.50933
Zillya Trojan.Lyposit.Win32.25
McAfee-GW-Edition BehavesLike.Win32.Generic.gh
Emsisoft Gen:Variant.Fugrafa.1845 (B)
Ikarus Trojan-Ransom.Lyposit
Jiangmin Trojan.Generic.bltxi
Avira TR/Dropper.Gen
Antiy-AVL Trojan[Ransom]/Win32.Blocker
Microsoft Ransom:Win32/Lyposit.B
Arcabit Trojan.Fugrafa.D735
AhnLab-V3 Trojan/Win32.Lyposit.R188188
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Gen:Variant.Fugrafa.1845
Cynet Malicious (score: 100)
Acronis suspicious
McAfee GenericRXAG-XO!C1C42BF03D3F
MAX malware (ai score=99)
VBA32 Trojan.Click
Malwarebytes Generic.Ransom.Malicious.DDS
Panda Trj/Genetic.gen
Rising Ransom.Lyposit!8.1E79 (TFE:dGZlOgWcc3BR8W6Grw)
Yandex Trojan.GenAsa!+NF32oP7OdY
SentinelOne Static AI – Malicious PE
eGambit Unsafe.AI_Score_72%
Fortinet W32/Generic.AP.34DAE6!tr
AVG Win32:Trojan-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM10.1.6A48.Malware.Gen

How to remove ML/PE-A + Troj/Lyposit-C?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

About “Malware.AI.299088769” infection

The Malware.AI.299088769 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

About “Malware.AI.4098582889” infection

The Malware.AI.4098582889 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Backdoor:Win32/Subseven.2_1 information

The Backdoor:Win32/Subseven.2_1 is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Marsilia.4611 removal tips

The Marsilia.4611 is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

Should I remove “Client-IRC.Win32.mIRC.616”?

The Client-IRC.Win32.mIRC.616 is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

About “Barys.67671” infection

The Barys.67671 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago