Malware

ML/PE-A + W32/Shodi-L removal guide

Malware Removal

The ML/PE-A + W32/Shodi-L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + W32/Shodi-L virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine ML/PE-A + W32/Shodi-L?


File Info:

name: 52A6A98785C1133E5751.mlw
path: /opt/CAPEv2/storage/binaries/7f41c18e21734648b80ad8fb24500cb7095a7ec6f190fff1fcee28e4a19e3f17
crc32: B4F0FA7D
md5: 52a6a98785c1133e575170c19e88dbe2
sha1: 81609a7d69775b2c4b625c5ae922e404a78d0aa2
sha256: 7f41c18e21734648b80ad8fb24500cb7095a7ec6f190fff1fcee28e4a19e3f17
sha512: 405b1b5d43fe30d2b02534fda46fd8fbcf2b43affc3af0aa2bcf0acf13d1dfa06445b320614dc53ec7692f3da8b766273d40655ce7087d312d99aafcf43bceb0
ssdeep: 1536:t13Bg0LtAiyBZjALCwC+mcPGZ7HSwwVlj/CT7j1Q:DBTzyBZjSBuUwwVlTCrK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104637E0337A4415EE0BB06749D96A7511B6EBC209F15AEEB43C2355F28B8BD0EE30D76
sha3_384: af78dd958369d1489ae7e1e78728f84abd0c4a04eb427945d29df9e4117a7d7bb45add118e99b81915d9d59de111b1cb
ep_bytes: e81c060000e94efdffffcccccccccccc
timestamp: 2010-11-20 08:51:26

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Welcome to Windows
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName: Setup
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SETUP.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

ML/PE-A + W32/Shodi-L also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Generic.n!c
MicroWorld-eScanTrojan.GenericKD.33606079
FireEyeGeneric.mg.52a6a98785c1133e
McAfeeArtemis!52A6A98785C1
SangforTrojan.Win32.Save.a
AlibabaVirus:Win32/Virut.fc0867c8
Cybereasonmalicious.785c11
SymantecTrojan.Gen.2
ESET-NOD32Win32/Virut.NBP
ClamAVWin.Virus.Virut-5901233-0
BitDefenderTrojan.GenericKD.33606079
AvastWin32:Vitro [Inf]
RisingVirus.Shodi!1.9B9C (CLASSIC)
Ad-AwareTrojan.GenericKD.33606079
EmsisoftTrojan.GenericKD.33606079 (B)
McAfee-GW-EditionArtemis
SophosML/PE-A + W32/Shodi-L
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.33606079
MaxSecurevirus.shohdi.i
MAXmalware (ai score=86)
Antiy-AVLVirus/Win32.Shohdi.a
MicrosoftProgram:Win32/Wacapew.C!ml
ALYacTrojan.GenericKD.33606079
VBA32Trojan.Wacatac
APEXMalicious
TencentWin32.Virus.Virut.Svhm
IkarusTrojan.Agent
FortinetW32/Vitro.BBD9!tr
AVGWin32:Vitro [Inf]

How to remove ML/PE-A + W32/Shodi-L?

ML/PE-A + W32/Shodi-L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment