Malware

ML/PE-A + Troj/Mdrop-CGE malicious file

Malware Removal

The ML/PE-A + Troj/Mdrop-CGE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Mdrop-CGE virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Troj/Mdrop-CGE?


File Info:

crc32: E037E7AA
md5: fbf366fcac5bcc862b8ec7c0a47e89ba
name: FBF366FCAC5BCC862B8EC7C0A47E89BA.mlw
sha1: b2aec8be6f06d128d35d6782a52c4cc643e328b4
sha256: 96782e44f6c0d73b5bdacb181ee444eb459d52cee937b7e306ec1bc0fe8e4be5
sha512: 2dfecd92465f4c876743225d6f21b56a89c8eca247f3480acd9529ba1b53b425a5648a350611c5a12f98c75675321508f49186004a4a46af983a29eae7b226c9
ssdeep: 24576:B/rR8iyo24O3K3QJfhgiaaQhJkGEBvhGVVArnj7bgmj/m:B/FEo2473QJ5QbHwhlj7C
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

ML/PE-A + Troj/Mdrop-CGE also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0030b2a81 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.32183
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent.8142
ALYacTrojan.GenericKD.34709477
CylanceUnsafe
ZillyaDropper.Agent.Win32.379508
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Mdrop.044fa2b0
K7GWTrojan ( 0030b2a81 )
Cybereasonmalicious.cac5bc
BaiduWin32.Trojan-Dropper.Agent.v
CyrenW32/Agent.FI.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/TrojanDropper.Agent.OBM
ZonerTrojan.Win32.36891
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Dropper.Ramnit-7081815-0
KasperskyTrojan-Dropper.Win32.Agent.gato
BitDefenderTrojan.GenericKD.34709477
NANO-AntivirusTrojan.Win32.Crypter.wpmb
ViRobotBackdoor.Win32.Hupigon.48640.I
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.GenericKD.34709477
TencentTrojan.Win32.Dropper.abh
Ad-AwareTrojan.GenericKD.34709477
SophosML/PE-A + Troj/Mdrop-CGE
ComodoTrojWare.Win32.TrojanDropper.Agent.~VQ@13ntw0
BitDefenderThetaGen:NN.ZexaF.34690.snJfaWhQ1Kbb
VIPRETrojanDropper.Win32.Agent.DO (v)
TrendMicroTROJ_AGENT.SMX
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.fbf366fcac5bcc86
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Crypter.gg
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.TE.A!ml
GridinsoftTrojan.Win32.Agent.vb!s2
ArcabitTrojan.Generic.D2119FE5
AegisLabTrojan.Win32.Agent.ljak
ZoneAlarmTrojan-Dropper.Win32.Agent.gato
GDataTrojan.GenericKD.34709477
AhnLab-V3Dropper/Win32.Crypter.R3134
McAfeegeneric!bg.fgl
MAXmalware (ai score=87)
VBA32Trojan.Win32.Genome.dfab
MalwarebytesRansom.Cerber
PandaGeneric Malware
TrendMicro-HouseCallTROJ_AGENT.SMX
RisingTrojan.Lock!1.B303 (CLOUD)
YandexTrojan.DR.Agent!R/81B4lC/3w
IkarusBackdoor.Win32.Hupigon
FortinetW32/Generic.AC.12FB!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove ML/PE-A + Troj/Mdrop-CGE?

ML/PE-A + Troj/Mdrop-CGE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment