Spy

ML/PE-A + Mal/SpyGate-A removal instruction

Malware Removal

The ML/PE-A + Mal/SpyGate-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/SpyGate-A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Steals private information from local Internet browsers
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Mal/SpyGate-A?


File Info:

crc32: F501C0CB
md5: 986486951e3a56d7dd4fe124e8abf385
name: 986486951E3A56D7DD4FE124E8ABF385.mlw
sha1: a661d5970cf5a73c3c347817fecad242ae4e0a5f
sha256: 398638fa30112b56cc7f63584881d433003e474e4cf0bd4c9dee00661dd3deec
sha512: f0ee2ef0f9928e3d9d0db0e56c3daa27978a20c25c81002d9b18c7e11e341fd38f58273aa014ca77d5793bb86cfa287537129a05f4c3dd8900d67c3be0f37c1a
ssdeep: 3072:v9Xwtyq/A1XqBwOEqjB7PU1xQ1vMKVxKIIlQ6:ytyqVBV8H4MS4
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft Corporation
Assembly Version: 1.4.0.0
InternalName: Stub.exe
FileVersion: 1.4
CompanyName: Microsoft Corporation
ProductVersion: 1.4
FileDescription: Microsoft Corporation
OriginalFilename: Stub.exe

ML/PE-A + Mal/SpyGate-A also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen1.5465
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Bladabindi.G3
ALYacTrojan.GenericKD.44922685
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.51e3a5
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AT
APEXMalicious
AvastMSIL:GenMalicious-BRD [Trj]
ClamAVWin.Dropper.njRAT-7400469-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.44922685
NANO-AntivirusTrojan.Win32.TrjGen.dklyhh
MicroWorld-eScanTrojan.GenericKD.44922685
TencentMalware.Win32.Gencirc.10c86a7b
Ad-AwareTrojan.GenericKD.44922685
SophosML/PE-A + Mal/SpyGate-A
ComodoBackdoor.MSIL.Bladabindi.FQ@5s6e92
BitDefenderThetaGen:NN.ZemsilF.34236.jq1@aqNJ5Pi
VIPREWin32.Malware!Drop
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBackDoor-FCLI!986486951E3A
FireEyeGeneric.mg.986486951e3a56d7
EmsisoftTrojan.GenericKD.44922685 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dwhio
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2F8561
MicrosoftTrojanDownloader:MSIL/Genmaldow.AE!bit
ArcabitTrojan.Generic.D2AD773D
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan-Spy.Keylogger.I
AhnLab-V3Trojan/Win32.Bladabindi.R85080
McAfeeBackDoor-FCLI!986486951E3A
MAXmalware (ai score=89)
VBA32Trojan.MSIL.gen.c.5
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.Agent!tkKiZYhXONc
IkarusTrojan.MSIL.Janeleiro
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SpyPSW.AVQ!tr
AVGMSIL:GenMalicious-BRD [Trj]

How to remove ML/PE-A + Mal/SpyGate-A?

ML/PE-A + Mal/SpyGate-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment