Malware

ML/PE-A + Mal/Salgorea-A removal tips

Malware Removal

The ML/PE-A + Mal/Salgorea-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Salgorea-A virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/Salgorea-A?


File Info:

crc32: 2C702B7A
md5: 6158dc53ac2faa3e6794b6359c5a51bd
name: 6158DC53AC2FAA3E6794B6359C5A51BD.mlw
sha1: e526cbd045b5ddab69f18c198f364c22a69f9310
sha256: cab1c9a7a6de26e0845a83327661af2cebad5daf85cf694d3e5965fabf4b7600
sha512: 12a05d1b70ffcfcc79611fd432e4a12f67439531df2668a1e9403331c2c06a2e50c5bef05f2cfc3593336eec9c00784a3cbb74d8a2dcc5420c5864c5307d6d40
ssdeep: 24576:N2oo60HPdt+1CRiY2eOBvcj3u10denVNaLHdaU/VU0iwHDK9q0jPvgfudxMAOejZ:Qoa1taC070d2itU0Y91jP4WvONVkYDWV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Mal/Salgorea-A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44375344
FireEyeGeneric.mg.6158dc53ac2faa3e
McAfeeGenericRXAO-HZ!6158DC53AC2F
CylanceUnsafe
ZillyaTrojan.Black.Win32.47443
SangforMalware
K7AntiVirusTrojan ( 004fdf0a1 )
BitDefenderTrojan.GenericKD.44375344
K7GWTrojan ( 004fdf0a1 )
Cybereasonmalicious.3ac2fa
CyrenW32/S-8e0acc48!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zusy-6291552-0
KasperskyBackdoor.Win32.Finfish.ow
NANO-AntivirusTrojan.Win32.Salgorea.ellsnj
TencentMalware.Win32.Gencirc.10b2f8c3
Ad-AwareTrojan.GenericKD.44375344
EmsisoftTrojan.GenericKD.44375344 (B)
ComodoTrojWare.Win32.Salgorea.AQ@73zvwa
F-SecureHeuristic.HEUR/AGEN.1117294
DrWebTrojan.MulDrop7.43397
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosML/PE-A + Mal/Salgorea-A
IkarusTrojan.Win32.Skeeyah
JiangminBackdoor.Finfish.y
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1117294
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Generic.D2A51D30
ZoneAlarmBackdoor.Win32.Finfish.ow
GDataTrojan.GenericKD.44375344
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1664134
Acronissuspicious
BitDefenderThetaAI:Packer.DFB6820820
ALYacTrojan.GenericKD.44375344
TACHYONBackdoor/W32.Finfish.1958400
VBA32Backdoor.Finfish
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Salgorea.AQ
RisingBackdoor.Finfish!8.192 (TFE:5:xsaFnaNFiqD)
YandexTrojan.GenAsa!Vl/tO0Uk9tE
SentinelOneStatic AI – Malicious PE – Downloader
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.39E2FE!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.057B.Malware.Gen

How to remove ML/PE-A + Mal/Salgorea-A?

ML/PE-A + Mal/Salgorea-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment