Malware

ML/PE-A + Mal/Swrort-D removal guide

Malware Removal

The ML/PE-A + Mal/Swrort-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Swrort-D virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine ML/PE-A + Mal/Swrort-D?


File Info:

crc32: 8E8B7B9B
md5: b767c187e759a2c5d83a73c358adfd1d
name: B767C187E759A2C5D83A73C358ADFD1D.mlw
sha1: ff8e5ed9599d9d145b317ed9f12ed8ab27f7aba1
sha256: 7752d4e9d33406eb854f3074dd9695075d8de334cff77d90eded180ab990c6d1
sha512: 2f40531b04eb0e399b46e458db3dd07fa146e362b63a5569ec13029187e39d36444619b72e7ec3bdd43824f943d91aacc07890ff0bc967658c929aaeb2374674
ssdeep: 24576:J0yeKlOEKqSeOpzYrlBhEsoMOTGyK6zlYzLhQ0zJ68VQWWRWqMZ:lOp1sbOTGOWkq3Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2020 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.74 (with embedded help)
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.74
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

ML/PE-A + Mal/Swrort-D also known as:

Elasticmalicious (high confidence)
ClamAVWin.Trojan.Swrort-5710536-0
McAfeeSwrort.d
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004baf121 )
Cybereasonmalicious.7e759a
CyrenW32/Swrort.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.ED
APEXMalicious
AvastWin32:SwPatch [Wrm]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.CryptZ.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanTrojan.CryptZ.Gen
Ad-AwareTrojan.CryptZ.Gen
SophosML/PE-A + Mal/Swrort-D
ComodoTrojWare.Win32.Rozena.A@4jwdqr
BitDefenderThetaGen:NN.ZexaF.34678.cD2@a0k2RWpi
VIPRETrojan.Win32.Swrort.B (v)
McAfee-GW-EditionSwrort.d
FireEyeGeneric.mg.b767c187e759a2c5
EmsisoftTrojan.CryptZ.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Gen2
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Meterpreter.gen!E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.CryptZ.Gen
Acronissuspicious
MAXmalware (ai score=80)
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpyVU9rRkGPFjMV4UbXKNA7)
YandexTrojan.Agent!OdTGHAYBKWY
IkarusTrojan.Win32.Rozena
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Swrort.C!tr
AVGWin32:SwPatch [Wrm]
Paloaltogeneric.ml

How to remove ML/PE-A + Mal/Swrort-D?

ML/PE-A + Mal/Swrort-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment