Ransom

ML/PE-A + Troj/Ransom-FXS removal tips

Malware Removal

The ML/PE-A + Troj/Ransom-FXS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Ransom-FXS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Puerto Rico)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine ML/PE-A + Troj/Ransom-FXS?


File Info:

name: DD61AA23EC606C94E86C.mlw
path: /opt/CAPEv2/storage/binaries/6968432da15540a1f0a8f5b09ce408ba0b66b052b51246ea6da7f34579dd8377
crc32: 6ECEDD68
md5: dd61aa23ec606c94e86ca5ac01496e9e
sha1: d87f7eb22bac404f9cbd876482b7e84476c4063d
sha256: 6968432da15540a1f0a8f5b09ce408ba0b66b052b51246ea6da7f34579dd8377
sha512: dba14ad00cb332fd17b0c583c68314be101767da0137e92355400f4f5695728ebe25108699998c7cbd0103a17bd3eac0b3305e573238d863ed6bdff09d1ef123
ssdeep: 49152:y1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1T1Tz:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0C68D303BD4C91EED69C9B0D5B31BE9633AE899E02B575B1580273F0C71B209E916ED
sha3_384: fc3797e91907ddd16f97b4c24ced710d5781dce1cc0076985908e8059f555f539e5f3e5594181f579fc75611bc283e01
ep_bytes: e8931a0000e978feffff8bff558bec81
timestamp: 2019-11-07 19:49:21

Version Info:

FileVersion: 1.0.5.4
InternalName: fbudbuss.ixi
LegalCopyright: Copyright (C) 2019, jlfmvlp
ProductVersion: 1.7.6
Translation: 0x0841 0x04c4

ML/PE-A + Troj/Ransom-FXS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.39179
MicroWorld-eScanTrojan.GenericKDZ.67001
FireEyeGeneric.mg.dd61aa23ec606c94
ALYacTrojan.GenericKDZ.67001
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056809d1 )
AlibabaRansom:Win32/NemptyCrypt.f08
K7GWTrojan ( 005663f21 )
Cybereasonmalicious.3ec606
BitDefenderThetaGen:NN.ZexaF.34182.@t0@ayFERtH
CyrenW32/Kryptik.BMO.gen!Eldorado
SymantecRansom.Nemty
ESET-NOD32a variant of Win32/Kryptik.HDDO
TrendMicro-HouseCallMal_Tofsee
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderTrojan.GenericKDZ.67001
NANO-AntivirusTrojan.Win32.Tofsee.hmsinw
AvastWin32:DropperX-gen [Drp]
EmsisoftTrojan.GenericKDZ.67001 (B)
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosML/PE-A + Troj/Ransom-FXS
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Tofsee.cni
AviraHEUR/AGEN.1134391
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.30AE74A
MicrosoftRansom:Win32/NemptyCrypt.SK!MTB
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.pef
GDataTrojan.GenericKDZ.67001
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPe.X2065
McAfeePacked-GBE!DD61AA23EC60
VBA32BScope.Trojan.Zbot.01439
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqmGlOMeXWBSGWwRPLuR9MV)
YandexTrojan.Agent!oXFPePSsf8s
IkarusPacked.Win32.Crypt
FortinetW32/GenKryptik.ELTY!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove ML/PE-A + Troj/Ransom-FXS?

ML/PE-A + Troj/Ransom-FXS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment