Malware

ML/PE-A + W32/VB-GAZ information

Malware Removal

The ML/PE-A + W32/VB-GAZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + W32/VB-GAZ virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ns1.chopsuwey.com
ns1.chopsuwey.net
ns1.chopsuwey.org
ns1.chopsuwey.biz
ns1.chopsuwey.info

How to determine ML/PE-A + W32/VB-GAZ?


File Info:

crc32: 84C51E13
md5: c1783a9d96fb0faac8a65c7cc6857619
name: C1783A9D96FB0FAAC8A65C7CC6857619.mlw
sha1: 882f80bdd850f511a5c612e86ba6c9f723c19034
sha256: 24855aa548bcf65fa6d0961537a8792d6173c6911b461f2405333c11b32a669e
sha512: 84c2e75695a49e0fb16c2a5ffaec58269df63253ae35fda2559bb9ffd774bdfaf80f72bd9a80c23f552e2f7b95894f1431768160483c2d4dfc849e3419979964
ssdeep: 12288:BuyIj9ZyFtXg+gZ+m2xnTU8/WDzmLlYTNccL4kIE+HYvbaZ7QAVVN:zIj0w1Z+VxNcczYvbo7QAVD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Entusiasto peaceable
InternalName: sulphonamido
FileVersion: 0.50
CompanyName: Entusiasto peaceable
LegalTrademarks: Entusiasto peaceable
Comments: Entusiasto peaceable
ProductName: Entusiasto peaceable
ProductVersion: 0.50
FileDescription: Entusiasto peaceable
OriginalFilename: sulphonamido.exe

ML/PE-A + W32/VB-GAZ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusEmailWorm ( 003c363a1 )
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74334
CAT-QuickHealWorm.VobfusMF.S18680912
ALYacTrojan.GenericKDZ.74334
CylanceUnsafe
ZillyaTrojan.ServStart.Win32.18796
SangforTrojan.Win32.Vobfus.fdja
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/Jorik.55d9bb00
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.d96fb0
BaiduWin32.Worm.VB.lg
SymantecBackdoor.Nitol
ESET-NOD32Win32/AutoRun.VB.AYH
APEXMalicious
AvastWin32:ServStart-B [Trj]
ClamAVWin.Packed.Kelihos-9652323-0
KasperskyTrojan.Win32.Jorik.Vobfus.fdja
BitDefenderTrojan.GenericKDZ.74334
Ad-AwareTrojan.GenericKDZ.74334
SophosML/PE-A + W32/VB-GAZ
ComodoWorm.Win32.Pronny.ABQ@4puwz1
BitDefenderThetaAI:Packer.A2D405D61F
VIPRETrojan.Win32.Nitol.b (v)
FireEyeGeneric.mg.c1783a9d96fb0faa
EmsisoftTrojan.GenericKDZ.74334 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraDDOS/Nitol.aoub
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.5
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataTrojan.GenericKDZ.74334
TACHYONTrojan/W32.Jorik.786432
AhnLab-V3Trojan/Win32.Jorik.R33547
Acronissuspicious
McAfeeVBObfus.ek
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2723729860
PandaTrj/Zbot.M
TrendMicro-HouseCallBKDR_KELIHOS.SMF
TencentWorm.Win32.Vobfus.m
YandexTrojan.GenAsa!IXrz+ynkfaw
IkarusBackdoor.Win32.Kelihos
MaxSecureTrojan.Malware.4385985.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:ServStart-B [Trj]
Paloaltogeneric.ml

How to remove ML/PE-A + W32/VB-GAZ?

ML/PE-A + W32/VB-GAZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment