Ransom

ML/PE-A + Troj/Ransom-AKD removal instruction

Malware Removal

The ML/PE-A + Troj/Ransom-AKD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Ransom-AKD virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Ransom-AKD?


File Info:

name: 161F40316CD528B1C75D.mlw
path: /opt/CAPEv2/storage/binaries/ea81ccad4b55a32f94c721fac4cf554f21c4900128b6a18b4ea87a746dedde58
crc32: DB222A29
md5: 161f40316cd528b1c75d55831c50452d
sha1: 7f526f4c8a8d0491bfe892efe12dbb22cb340363
sha256: ea81ccad4b55a32f94c721fac4cf554f21c4900128b6a18b4ea87a746dedde58
sha512: 46bd6f906ccc71a5e9a05330ba21676ed260c2b85e440493a556796937e01347a1d73d09ab775c1380d6ee1b8dee47724bc8be2dfd3e9de9a6f840f5872eb327
ssdeep: 384:N9xdUqG1E/ew1Zz/aH59N1Drb+E1H63Vs17o/WsB:PxdIm/hZGHrqE1H63A7o/WI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14AA2C4B773D24CF1F6A707B0A876624BA49074D153D236FF4A1E9E104D02AC6EAF12C9
sha3_384: 2148b005e445880d1cfcb7f3c82e479f69dd69fd7d5494e452f6c30bab6c9602a8e61b8c9391f2874fc3b50c7dd63008
ep_bytes: 558bec83ec4456ff150c2040008bf08a
timestamp: 1992-06-01 18:44:46

Version Info:

0: [No Data]

ML/PE-A + Troj/Ransom-AKD also known as:

BkavW32.FamVT.GeND.Trojan
MicroWorld-eScanTrojan.GenericKD.1796217
FireEyeGeneric.mg.161f40316cd528b1
CAT-QuickHealTrojanDownloader.Upatre.AA4
ALYacTrojan.GenericKD.1796217
CylanceUnsafe
VIPRETrojan.Win32.Upatre.buu (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.1796217
K7GWTrojan-Downloader ( 0048f6391 )
K7AntiVirusTrojan-Downloader ( 0048f6391 )
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Generic.CNGO
CyrenW32/Trojan.INCI-3183
SymantecRansom.Cryptodefense
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan-Ransom.Win32.Cryptodef.bvj
NANO-AntivirusTrojan.Win32.Panda.ddsitr
RisingDownloader.Waski!1.A489 (RDMK:cmRtazoyKcjAlwSwiYxN0tQLP2n9)
EmsisoftTrojan.GenericKD.1796217 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
DrWebTrojan.PWS.Panda.7591
ZillyaTrojan.Cryptodef.Win32.125
TrendMicroTROJ_UPATRE.SMN6
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
SophosML/PE-A + Troj/Ransom-AKD
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cryptodef.ag
AviraTR/ATRAPS.A.1656
Antiy-AVLTrojan/Generic.ASMalwS.B574AC
MicrosoftTrojan:Win32/Zbot.svfs!MTB
SUPERAntiSpywareTrojan.Agent/Gen-KD
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Necurs.R115439
McAfeeDownloader-FSH
MAXmalware (ai score=89)
VBA32BScope.TrojanPSW.Panda
MalwarebytesMalware.AI.2456335957
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMN6
TencentTrojan.Win32.Downloader.bvj
YandexTrojan.Cryptodef!/wlz6YFVXN4
IkarusTrojan.Win32.Bublik
eGambitUnsafe.AI_Score_99%
FortinetW32/Waski.A!tr.dldr
BitDefenderThetaGen:NN.ZexaF.34182.bqX@aiLlmVgO
AVGWin32:Trojan-gen
Cybereasonmalicious.16cd52
AvastWin32:Trojan-gen
MaxSecureTrojan.Upatre.Gen

How to remove ML/PE-A + Troj/Ransom-AKD?

ML/PE-A + Troj/Ransom-AKD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment