Malware

ML/PE-A + Troj/MSIL-RRG removal guide

Malware Removal

The ML/PE-A + Troj/MSIL-RRG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/MSIL-RRG virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine ML/PE-A + Troj/MSIL-RRG?


File Info:

crc32: 123E0E14
md5: e2e027360aa11a532949fb6c013009d5
name: E2E027360AA11A532949FB6C013009D5.mlw
sha1: 2488a833ee33ea4ce3ff0e5e7615e35d647816e2
sha256: 13c2ff62d1e29d6e88c828851f842b17acb6293da92bdf5223e87a67bf00ed31
sha512: 240a63a3c245d1dd963cc33b290796e646276f9488692037f26009efde4ad39b9c6af6d0c4d21ca19b5ade4a677b4b2d7e83003a519c2dbfbf408c086ca0f04a
ssdeep: 12288:IlLTGNWHCM2K4CC3/TEggDN1BZkW0TJkgig+DAkmEYd:INT43CcLEDBZKJW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 x5faex8f6fx4e2dx56fd 2015
Assembly Version: 1.0.0.0
InternalName: SafeProcessHand.exe
FileVersion: 1.0.0.0
CompanyName: x5faex8f6fx4e2dx56fd
LegalTrademarks:
Comments:
ProductName: VirtualRouter
ProductVersion: 1.0.0.0
FileDescription: VirtualRouter
OriginalFilename: SafeProcessHand.exe

ML/PE-A + Troj/MSIL-RRG also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.MSIL.Noon.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.1031
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37589907
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3ee33e
CyrenW32/MSIL_Kryptik.FOI.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.ACUF
ZonerTrojan.Win32.119314
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.37589907
MicroWorld-eScanTrojan.GenericKD.37589907
Ad-AwareTrojan.GenericKD.37589907
SophosML/PE-A + Troj/MSIL-RRG
ComodoTrojWare.Win32.UMal.mtgku@0
BitDefenderThetaGen:NN.ZemsilF.34142.Cm0@aeUqJee
McAfee-GW-EditionBehavesLike.Win32.Fareit.gc
FireEyeGeneric.mg.e2e027360aa11a53
EmsisoftTrojan.GenericKD.37589907 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Swotter.agduj
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.CUC!MTB
GDataTrojan.GenericKD.37589907
AhnLab-V3Trojan/Win.SnakeKeylogger.R441577
McAfeeAgentTesla-FDCV!E2E027360AA1
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00IG21
IkarusTrojan-Spy.Keylogger.Snake
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ACUH!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove ML/PE-A + Troj/MSIL-RRG?

ML/PE-A + Troj/MSIL-RRG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment