Ransom

Should I remove “ML/PE-A + Mal/Ransom-AO”?

Malware Removal

The ML/PE-A + Mal/Ransom-AO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Ransom-AO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/Ransom-AO?


File Info:

crc32: B165AC74
md5: 4e145524c5fbcb726d24a843f41c8190
name: 4E145524C5FBCB726D24A843F41C8190.mlw
sha1: 6753227156dc0a7c0cf7186aa4c629e44cd036c1
sha256: 5dc1a02cdf65590022744afd5d063b70158883bafca6fe75f51facd665294664
sha512: de4d526ef80112739c8fedbb410331366599baec33c1ed592f912bd3fecc28d175082b1b01b022380ca61d59faab2f53cbeb75a9fa65eb19c16377b5aa4976ae
ssdeep: 1536:zQ2sIKLqVye3+cBJHsajBBbUo4VauIGuh/RrPF+HDL:zsIg5cBpsajbgo4Va/ZRjF+HDL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Mal/Ransom-AO also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0040f3c81 )
DrWebTrojan.Winlock.8128
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Urausy.C
ALYacGen:Heur.VIZ.8
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.930194
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Urausy.f5936b1d
K7GWTrojan ( 0040f3c81 )
Cybereasonmalicious.4c5fbc
CyrenW32/FakeAlert.WR.gen!Eldorado
SymantecPacked.Generic.417
ESET-NOD32Win32/LockScreen.APR
APEXMalicious
AvastWin32:Reveton-RX [Trj]
ClamAVWin.Ransomware.Generickdz-9652412-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.8
NANO-AntivirusTrojan.Win32.RiskGen.cqoqaw
SUPERAntiSpywareTrojan.Agent/Gen-LockScreen
MicroWorld-eScanGen:Heur.VIZ.8
TencentWin32.Trojan.Lockscreen.Pdmi
Ad-AwareGen:Heur.VIZ.8
SophosML/PE-A + Mal/Ransom-AO
ComodoTrojWare.Win32.Kryptik.BAQC@4xm2qg
BitDefenderThetaGen:NN.ZexaF.34628.gqW@aqbYuWgi
VIPRETrojan.Win32.FakeAV.ka (v)
McAfee-GW-EditionRansom-FBXU!4E145524C5FB
FireEyeGeneric.mg.4e145524c5fbcb72
EmsisoftGen:Heur.VIZ.8 (B)
JiangminTrojan/Foreign.fkw
WebrootW32.Rogue.Gen
AviraTR/Urausy.9830315
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Urausy.C
ArcabitTrojan.VIZ.8
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Heur.VIZ.8
TACHYONTrojan/W32.Foreign.98304.WK
AhnLab-V3Trojan/Win32.LockScreen.R66413
Acronissuspicious
McAfeeRansom-FBXU!4E145524C5FB
MAXmalware (ai score=100)
VBA32Hoax.Foreign
MalwarebytesTrojan.FakeAlert.RGenX
PandaTrj/Resdec.HEU
RisingTrojan.Kryptik!1.66AB (CLOUD)
YandexTrojan.Foreign!0fm0SfduXDw
IkarusTrojan.Win32.FakeAV
FortinetW32/SystemSecurity.AL!tr
AVGWin32:Reveton-RX [Trj]
Qihoo-360Win32/Ransom.Urausy.HwgAts4A

How to remove ML/PE-A + Mal/Ransom-AO?

ML/PE-A + Mal/Ransom-AO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment