Malware

ML/PE-A + W32/OYSoul-Gen malicious file

Malware Removal

The ML/PE-A + W32/OYSoul-Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + W32/OYSoul-Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine ML/PE-A + W32/OYSoul-Gen?


File Info:

name: AC6E924C4209C6981D27.mlw
path: /opt/CAPEv2/storage/binaries/73fe610272c889dbe98d6be2015c4d8932706094588032072cb8243ab413cf61
crc32: B75D6ED0
md5: ac6e924c4209c6981d27f101fc5802e9
sha1: 7a48d1209553f0dfaf49870e22638f7a109ae2f3
sha256: 73fe610272c889dbe98d6be2015c4d8932706094588032072cb8243ab413cf61
sha512: cf10f6bcf812953c96f099ecb9d88656fff1010f8c791e591c9f42ff4735e2fcfe45040977f920fb133d42c6d2136d3923b969074adda199c4ac39774a862072
ssdeep: 6144:yF/WqWcLcls2X/uyX/HEpgPCbV1fNm3Tx0TpKidq2o7D29fx+J9zyHqYLL+o63kI:y8QcfF/HEp64lQaVH8vaZ/M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168D46B0EFFA05C36D21242328DA2F36E61ADBE741961460777487B0DE9B1FD1B92871B
sha3_384: 11dc62b9e45d78498eb8362c147cd512a599e6bfba5d62a95f2d366324edcb3efeb96c04ecc9ae06361130f4b93d6408
ep_bytes: 68488f4000e8f0ffffff000000000000
timestamp: 2008-06-08 14:36:24

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 2146
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: avp
OriginalFilename: avp.exe

ML/PE-A + W32/OYSoul-Gen also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.SoulClose.E
FireEyeGeneric.mg.ac6e924c4209c698
ALYacWin32.Worm.SoulClose.E
ZillyaWorm.VB.Win32.481
K7AntiVirusP2PWorm ( 004e419d1 )
K7GWP2PWorm ( 004e419d1 )
Cybereasonmalicious.c4209c
BaiduWin32.Worm.VB.bc
CyrenW32/Worm.Soul.gen!Eldorado
SymantecW32.Fujacks.C
ESET-NOD32a variant of Win32/AutoRun.VB.HG
APEXMalicious
ClamAVWin.Worm.Soulclose-7085422-0
KasperskyWorm.Win32.VB.rc
BitDefenderWin32.Worm.SoulClose.E
NANO-AntivirusTrojan.Win32.VB.ooto
SUPERAntiSpywareWorm.SoulClose/Variant
AvastWin32:VB-JHS [Wrm]
TencentMalware.Win32.Gencirc.114b9994
Ad-AwareWin32.Worm.SoulClose.E
EmsisoftWin32.Worm.SoulClose.E (B)
ComodoVirus.Win32.VB.~A@ziv7
DrWebWin32.HLLW.Autoruner.2173
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.jm
SophosML/PE-A + W32/OYSoul-Gen
SentinelOneStatic AI – Malicious PE
JiangminWorm/VB.pcu
AviraTR/VB.dek.2
Antiy-AVLTrojan/Generic.ASMalwS.128E01C
MicrosoftWorm:Win32/Soulclose.B
GDataWin32.Trojan.PSE.136NMWS
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VB.R287861
McAfeeArtemis!AC6E924C4209
MAXmalware (ai score=86)
VBA32Trojan.Downloader
YandexWorm.VB!R9/ixfALmfo
IkarusVirus.Worm.Win32.VB
FortinetW32/VB.MJU!tr
BitDefenderThetaAI:Packer.254A2CEF15
AVGWin32:VB-JHS [Wrm]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove ML/PE-A + W32/OYSoul-Gen?

ML/PE-A + W32/OYSoul-Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment