Malware

How to remove “ML/PE-A + Mal/Generic-L”?

Malware Removal

The ML/PE-A + Mal/Generic-L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Generic-L virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/Generic-L?


File Info:

crc32: 8D4979A8
md5: f6ec322450da7ee7f89092d4f7fb370a
name: F6EC322450DA7EE7F89092D4F7FB370A.mlw
sha1: 50792442361e3fd992f17361cb1611ced431aad5
sha256: ad91d4f5be9178df7b570e6db5a8d1fded1a95e843b30be108ed821b33504b33
sha512: edf1d87789957597355c46c6343e9718eae70d2b073d5a6ddef4c610007e297aaac877d17a13730f1d8ebc4e1b17d84c9bc2e546d99bb30e63e402bdfef64955
ssdeep: 192:3rqvqucLm8WrcchKMqiJQjwPRn4sU9Vw:3rUqbOPhKMqkPws
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Mal/Generic-L also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0029be2d1 )
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.6
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Kazy.20419
CylanceUnsafe
ZillyaTrojan.Mbro.Win32.346
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Genasom.e6e459b6
K7GWTrojan ( 0029be2d1 )
Cybereasonmalicious.450da7
CyrenW32/Ransom.X.gen!Eldorado
SymantecTrojan.Bootlock.B
ESET-NOD32a variant of Win32/MBRlock.R
APEXMalicious
AvastMBR:Ransom-A [Rtk]
ClamAVWin.Trojan.Ransom-43
KasperskyTrojan-Ransom.Win32.Mbro.rv
BitDefenderGen:Variant.Kazy.20419
NANO-AntivirusTrojan.Win32.Mbro.ctoicc
ViRobotTrojan.Win32.A.Mbro.139264
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
MicroWorld-eScanGen:Variant.Kazy.20419
TencentWin32.Trojan.Mbro.Efuq
Ad-AwareGen:Variant.Kazy.20419
SophosML/PE-A + Mal/Generic-L
ComodoTrojWare.Win32.Trojan.Agent.~CRP@3xxg3u
BitDefenderThetaAI:Packer.1BE16E5D1D
VIPRETrojan.Win32.Ransom.dva (v)
TrendMicroTROJ_RANSOM_BL13015C.TOMC
McAfee-GW-EditionRansom-FIT!F6EC322450DA
FireEyeGeneric.mg.f6ec322450da7ee7
EmsisoftGen:Variant.Kazy.20419 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.ifva
WebrootW32.Trojan.Gen
AviraBOO/Ransom.AB
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/Genasom.DV
AegisLabTrojan.Win32.Mbro.luc6
GDataGen:Variant.Kazy.20419
TACHYONTrojan/W32.Small.10240.IS
AhnLab-V3Trojan/Win32.Mbro.C67070
Acronissuspicious
McAfeeRansom-FIT!F6EC322450DA
MAXmalware (ai score=100)
VBA32Trojan.Ransom.5705
MalwarebytesRansom.FileCryptor
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM_BL13015C.TOMC
RisingTrojan.MBRlock!1.66BD (CLOUD)
IkarusTrojan-Ransom.Mbro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/MBRlock.C!tr
AVGMBR:Ransom-A [Rtk]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Genasom.HxMBEpsA

How to remove ML/PE-A + Mal/Generic-L?

ML/PE-A + Mal/Generic-L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment