Malware

ML/PE-A + W32/Renamer-K removal tips

Malware Removal

The ML/PE-A + W32/Renamer-K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + W32/Renamer-K virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine ML/PE-A + W32/Renamer-K?


File Info:

crc32: CAF1B0C9
md5: 0c282de67d2860170d3704a4c2249e69
name: 0C282DE67D2860170D3704A4C2249E69.mlw
sha1: 8281f169e7164d3137f6eb9c8f28d6d278633194
sha256: fa9fff1f3235fdc2da833416425db60023c2716bb53c0a4872d1635e6001a6cf
sha512: 0c64f5c483f40935f56a394e54c841a5a75700ddca867ee65b0521a45e28df15262c3ac2e69ff2930abee6f7932b66d461f331e6c62dc5f5d2d5a6af3e75b972
ssdeep: 12288:9rMIztyCK5x8CBmn+RrNbEyWYa0Ie1vUx9V2:7ZyCA8CBmn+RrNj9ay5I2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + W32/Renamer-K also known as:

BkavW32.WangpuiNWP.Trojan
K7AntiVirusTrojan ( 000c8b551 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.58276
CynetMalicious (score: 100)
CAT-QuickHealW32.Grenam.A9
ALYacTrojan.GenericKD.45649623
CylanceUnsafe
ZillyaWorm.Delf.Win32.869
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Grenam.371
K7GWTrojan ( 004d4f8e1 )
Cybereasonmalicious.67d286
BaiduWin32.Worm.Delf.bi
CyrenW32/A-2f9e86a4!Eldorado
SymantecW32.Tapin
ESET-NOD32Win32/Delf.NRJ
ZonerTrojan.Win32.87681
APEXMalicious
AvastWin32:Renamer-F [Trj]
ClamAVWin.Virus.Gnamer-1
KasperskyVirus.Win32.Renamer.j
BitDefenderTrojan.GenericKD.45649623
NANO-AntivirusTrojan.Win32.Renamer.lnwkz
ViRobotWin32.Renamer.A
MicroWorld-eScanTrojan.GenericKD.45649623
TencentTrojan.Win32.Renamer.ttk
Ad-AwareTrojan.GenericKD.45649623
SophosML/PE-A + W32/Renamer-K
ComodoWorm.Win32.Delf.nj@4ri78u
BitDefenderThetaGen:NN.ZelphiF.34692.GKW@aeXOH5di
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.GRENAM.SM
McAfee-GW-EditionBehavesLike.Win32.Gnamer.hh
FireEyeGeneric.mg.0c282de67d286017
EmsisoftTrojan.GenericKD.45649623 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Delf.yc
WebrootW32.Malware.gen
AviraW32/Renamer.A
MicrosoftVirus:Win32/Grenam.A
GridinsoftVirus.Win32.Grenam.sb!s1
AegisLabVirus.Win32.Renamer.tn9X
GDataTrojan.GenericKD.45649623
TACHYONWorm/W32.DP-Renamer.534016
AhnLab-V3Trojan/Win32.Renamer.R54474
Acronissuspicious
McAfeeW32/Gnamer
MAXmalware (ai score=83)
VBA32TScope.Trojan.Delf
MalwarebytesRenamer.Virus.FileInfector.DDS
PandaTrj/Renamer.H
TrendMicro-HouseCallTrojan.Win32.GRENAM.SM
RisingTrojan.Win32.Renamer.g (CLOUD)
YandexTrojan.GenAsa!bFkr50Cc7zI
IkarusDropper.Patched
MaxSecureVirus.W32.Renamer.J
FortinetW32/Renamer.BQT!tr
AVGWin32:Renamer-F [Trj]
Paloaltogeneric.ml

How to remove ML/PE-A + W32/Renamer-K?

ML/PE-A + W32/Renamer-K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment