Malware

How to remove “ML/PE-A + Mal/Tinba-AB”?

Malware Removal

The ML/PE-A + Mal/Tinba-AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Tinba-AB virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Japanese
  • Detects Avast Antivirus through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Attempts to access Bitcoin/ALTCoin wallets
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/Tinba-AB?


File Info:

crc32: B079FD50
md5: 05786fdb575f38fae38c396a642c9854
name: 05786FDB575F38FAE38C396A642C9854.mlw
sha1: 43e76845db047fe30a0c31f65c11931d347d5ef0
sha256: 0043909635a98f80b462cf654008e60b31fac0022f73c8a08b234b7c359803f4
sha512: 2ae1a8389d2a5298adb682dafeca0216ef521524c094ab8ffbba46ad875b4dde747faafa96e15990037d3cffdb68e0839f08e07f52b36e7971bb68688c5a09ba
ssdeep: 12288:YuA4CGTm98Tf5Yw8v/C3BvTGwaO+Q+PxSDOE:YuApowHMSPOOE
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2016-2020
CompanyName: MusicMatch
Comments:
ProductName: Atrocities Artiste
ProductVersion: 85, 53, 127, 91
FileDescription: Bebop
OriginalFilename: Centric.exe

ML/PE-A + Mal/Tinba-AB also known as:

K7AntiVirusSpyware ( 0055e3db1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.1000
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Patched.Win64.2634
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanSpy:Win32/Skeeyah.92ae087b
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.b575f3
SymantecTrojan.Gen.2
ESET-NOD32Win32/Spy.Shiz.NCT
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Yakes.eaukss
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.10ba0dc7
Ad-AwareTrojan.Cripack.Gen.1
SophosML/PE-A + Mal/Tinba-AB
ComodoMalware@#17vow2900zexb
F-SecureHeuristic.HEUR/AGEN.1113913
BitDefenderThetaGen:NN.ZexaF.34266.Jq0@aCJou!iO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Rootkit.ht
FireEyeGeneric.mg.05786fdb575f38fa
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminVariant.Symmi.ahk
AviraHEUR/AGEN.1113913
Antiy-AVLTrojan/Generic.ASMalwS.16516CF
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
GDataTrojan.Cripack.Gen.1
AhnLab-V3Trojan/Win32.RL_Teslacrypt.R285867
McAfeeGeneric.dzr
MAXmalware (ai score=100)
VBA32SScope.Malware-Cryptor.Drixed
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.85 (RDML:abBxqt6uJWs7K4MyxB3wSQ)
YandexTrojanSpy.Shiz!CKZzYZSLGsY
IkarusTrojan-Ransom.Locky
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EQEH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove ML/PE-A + Mal/Tinba-AB?

ML/PE-A + Mal/Tinba-AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment