Malware

ML/PE-A + Mal/GamePSW-L removal tips

Malware Removal

The ML/PE-A + Mal/GamePSW-L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/GamePSW-L virus can do?

  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine ML/PE-A + Mal/GamePSW-L?


File Info:

name: 2BEA49E488F8EC5FAEB1.mlw
path: /opt/CAPEv2/storage/binaries/6875c007461138a1491886ae27f2db2c02badfde12109a0b32592b23f562c0d3
crc32: 82A9F457
md5: 2bea49e488f8ec5faeb1e1d3d8670613
sha1: 7490449bf72e52ca68da9fca380c9f252ce09e41
sha256: 6875c007461138a1491886ae27f2db2c02badfde12109a0b32592b23f562c0d3
sha512: e42a85219c276eb6fd15907ed1841db9bc19ebe3ac9003d4c657e8266d7ce434d5c932ac1625ceda273e297715093d7efb50d705647529e6e56d494bb24a8d35
ssdeep: 3072:gZd+0VQXJFMC1wIa6FlGYGL78RNwYJhbYKg/y7FChfgAJGtTBf3zjXG:AK5+C1C688Ths7/yRKffGtTBLjXG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190443911E7C582D7D5826DBD9F8B3232DB35ACA825381E17372046D999B3883B1A3773
sha3_384: 557174a226e342205d5a44d469949bbba6760a3e2dcef483d87dbf794f3827290aba476ca031b72e29f16762ce729e6a
ep_bytes: 558bec6aff6890bb4300680c55430064
timestamp: 2011-06-28 06:48:02

Version Info:

0: [No Data]

ML/PE-A + Mal/GamePSW-L also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Bandito.1290
MicroWorld-eScanGen:Variant.Unruy.5
FireEyeGeneric.mg.2bea49e488f8ec5f
CAT-QuickHealTrojanDownloader.Unruy.Q
ALYacGen:Variant.Unruy.5
MalwarebytesMalware.AI.712848986
K7AntiVirusTrojan ( 002589dc1 )
K7GWTrojan ( 002589dc1 )
Cybereasonmalicious.488f8e
ArcabitTrojan.Unruy.5
BitDefenderThetaGen:NN.ZexaF.34062.qqX@a8HRoNnb
CyrenW32/Unruy.H.gen!Eldorado
SymantecW32.Unruy.A
ESET-NOD32a variant of Win32/Kryptik.AJLF
TrendMicro-HouseCallTROJ_AGENT_056159.TOMB
ClamAVWin.Malware.Unruy-9840577-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Unruy.5
NANO-AntivirusTrojan.Win32.Renamer.lloxl
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Unruy-B [Trj]
TencentMalware.Win32.Gencirc.10b0cfcb
Ad-AwareGen:Variant.Unruy.5
TACHYONTrojan/W32.Agent.271371.B
SophosML/PE-A + Mal/GamePSW-L
ComodoTrojWare.Win32.TrojanClicker.Cycler.CP@44jnry
BaiduWin32.Trojan.Kryptik.ak
TrendMicroTROJ_AGENT_056159.TOMB
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
EmsisoftGen:Variant.Unruy.5 (B)
IkarusBackdoor.Win32.Banito
JiangminBackdoor/Banito.zr
AviraTR/Dldr.Unruy.QA
MicrosoftTrojanDownloader:Win32/Unruy.Q
GDataGen:Variant.Unruy.5
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Banito.C100677
Acronissuspicious
McAfeeGenericRXBH-AF!2BEA49E488F8
MAXmalware (ai score=87)
VBA32BScope.Worm.Chiviper
APEXMalicious
RisingTrojan.Kryptik!1.B59A (CLASSIC)
YandexTrojan.GenAsa!w62A35WWWXg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banito.CN!tr
WebrootW32.Trojan.Gen
AVGWin32:Unruy-B [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Mal/GamePSW-L?

ML/PE-A + Mal/GamePSW-L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment