Malware

About “ML/PE-A + Troj/Zbot-COF” infection

Malware Removal

The ML/PE-A + Troj/Zbot-COF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Zbot-COF virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Zbot-COF?


File Info:

crc32: AECFEA55
md5: 7419a33ddf3ae87c5a93fa24aa2bcb73
name: 7419A33DDF3AE87C5A93FA24AA2BCB73.mlw
sha1: 1ba1a45a32406a11e9a00dd2c53601d42f65cb39
sha256: b89a39c8f9887a5164a658727d29d69ab11bc08e8348a994ec1704b8c0e5ed81
sha512: 374606110c50ef39b49d50adfbce414c223e4a110c715aab0468b0a71f803f7fa67cb46c6fbc1cb4c624353b923faa8457c3935db35139f81a2002967e47fd74
ssdeep: 6144:q+oUb5UlNVf9MPLMCNky7SHIqTDK4O+mEaDrELERi:PPSl3uiuKh3KlxEgEf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Troj/Zbot-COF also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0040f2c01 )
LionicTrojan.Win32.Generic.4!c
DrWebBackDoor.IRC.Bot.1725
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.Cerber.2
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.139058
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanPSW:Win32/Yakes.c2897a80
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.ddf3ae
CyrenW32/A-14b7c56a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Yakes-229
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Ransom.Cerber.2
NANO-AntivirusTrojan.Win32.Bot.bbxgps
ViRobotTrojan.Win32.A.Yakes.171008.B
MicroWorld-eScanGen:Heur.Ransom.Cerber.2
TencentMalware.Win32.Gencirc.10bf44ac
Ad-AwareGen:Heur.Ransom.Cerber.2
SophosML/PE-A + Troj/Zbot-COF
ComodoMalware@#3lu6j5kpi1ny0
VIPRETrojan.Win32.Zbot.cof (v)
TrendMicroTROJ_JORIK_BK084717.TOMC
McAfee-GW-EditionBehavesLike.Win32.ZBot.dc
FireEyeGeneric.mg.7419a33ddf3ae87c
EmsisoftGen:Heur.Ransom.Cerber.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Yakes.fwo
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.4D331
MicrosoftPWS:Win32/Zbot
GDataGen:Heur.Ransom.Cerber.2
AhnLab-V3Trojan/Win32.Chifrax.R37671
McAfeePWS-Zbot.gen.aly
MAXmalware (ai score=100)
VBA32Trojan.Yakes
MalwarebytesMalware.AI.763329815
PandaGeneric Malware
TrendMicro-HouseCallTROJ_JORIK_BK084717.TOMC
RisingTrojan.Generic@ML.98 (RDML:XnMESPreFb6cGaEX/xTIMQ)
YandexTrojan.GenAsa!7JdWNRqvOO0
IkarusTrojan.Win32.Yakes
FortinetW32/Injector.VWW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HxQBEpsA

How to remove ML/PE-A + Troj/Zbot-COF?

ML/PE-A + Troj/Zbot-COF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment