Malware

ML/PE-A + Mal/VB-UY removal guide

Malware Removal

The ML/PE-A + Mal/VB-UY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/VB-UY virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine ML/PE-A + Mal/VB-UY?


File Info:

name: 11097A7641266D97B509.mlw
path: /opt/CAPEv2/storage/binaries/5258b751d1690fdd111fa6f15d59bdcf53d1dae86cdfe3fb2f5eeeeaa6cea6c2
crc32: 9FD12EE0
md5: 11097a7641266d97b509a441e1e20585
sha1: 64264efeb0814db9789a0481b15ea885846fbe1d
sha256: 5258b751d1690fdd111fa6f15d59bdcf53d1dae86cdfe3fb2f5eeeeaa6cea6c2
sha512: 9af56a337ada5dcd8d5d501778eb2b864790f9b04b2b296050be0dd7e0b75da582db9c4ec8de81bd7545344d6b0539b98727b34450777b2aa297ad9a19d48c6f
ssdeep: 6144:v0dAmC9ma7LM+EuoN5Maj//G1DSMMyTDb1XJTxUoSg:08n7g+Ev5F/2DSMMSDbdJdUoSg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF54237E527B766CC14B03351EB28F890428FE1C92CD016BF0D5F99A97BCA446B361B8
sha3_384: cbdce31d011393175a6d53264c3dab066511aed93553124173c6401e62affb5828cc3f8d1d1f94cf2b69804c9b6d33a1
ep_bytes: 60be00305b008dbe00e0e4ff5789e58d
timestamp: 2011-02-21 19:16:29

Version Info:

Translation: 0x0409 0x04b0
Comments: EWXFNWXDO
CompanyName: WVQPRKIRL
FileDescription: PZCSYTDUA
ProductName: IHZVLTAJK
FileVersion: 17.15.0009
ProductVersion: 17.15.0009
InternalName: undgpxa
OriginalFilename: undgpxa.exe

ML/PE-A + Mal/VB-UY also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.ManBat.1
FireEyeGeneric.mg.11097a7641266d97
ALYacGen:Heur.ManBat.1
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.129311
K7AntiVirusTrojan ( 0021a0b51 )
AlibabaTrojan:Win32/Injector.29204d8a
K7GWTrojan ( 0021a0b51 )
Cybereasonmalicious.641266
BitDefenderThetaAI:Packer.EC0F5AC920
CyrenW32/Trojan.FDCC-8756
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EYU
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.Drop.ecjudo
AvastFileRepMalware
TencentMalware.Win32.Gencirc.11d93105
Ad-AwareGen:Heur.ManBat.1
EmsisoftGen:Heur.ManBat.1 (B)
ComodoTrojWare.Win32.VBKrypt.cjub@4vg4ee
DrWebTrojan.MulDrop3.21280
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win32.Spyeye.dc
SophosML/PE-A + Mal/VB-UY
IkarusTrojan.Win32.VBKrypt
GDataGen:Heur.ManBat.1
JiangminTrojan/VBKrypt.hgqd
eGambitUnsafe.AI_Score_91%
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.18A0D35
GridinsoftRansom.Win32.Sabsik.sa
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeePWS-Spyeye.el
VBA32SScope.Trojan.VBRA.6299
MalwarebytesMalware.AI.4251118812
YandexTrojan.VBKrypt!6Cs3ayBiGQk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.MQI!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove ML/PE-A + Mal/VB-UY?

ML/PE-A + Mal/VB-UY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment