Ransom:Win32/Play!ml Virus “Play!ml” Removal

Written by Wilbur Woodham

If you spectate the alert of Ransom:Win32/Play!ml detection, it appears that your PC has a problem. All malicious programs are dangerous, without any deviations. Play!ml is a malicious application that aims at opening your computer to further threats. Most of of the modern malware examples are complex, and can download other viruses. Getting the Ransom:Win32/Play!ml malware often equals to getting a malicious thing which can act like spyware or stealer, downloader, and a backdoor. Spectating this detection means that you need to perform the malware removal as fast as you can.

Any malware exists with the only target – gain money on you. And the programmers of these things are not thinking about morality – they use all possible ways. Stealing your personal data, receiving the payments for the banners you watch for them, exploiting your hardware to mine cryptocurrencies – that is not the complete list of what they do. Do you want to be a riding steed? That is a rhetorical question.

GridinSoft Anti-Malware Review
It is better to prevent, than repair and repent!
When we talk about the intrusion of unfamiliar programs into your computer’s work, the proverb “Forewarned is forearmed” describes the situation as accurately as possible. Gridinsoft Anti-Malware is exactly the tool that is always useful to have in your armory: fast, efficient, up-to-date. It is appropriate to use it as an emergency help at the slightest suspicion of infection.
Gridinsoft Anti-Malware 6-day trial available.
EULA | Privacy Policy | 10% Off Coupon
Subscribe to our Telegram channel to be the first to know about news and our exclusive materials on information security.

What is Ransom:Win32/Play!ml virus?

The Ransom:Win32/Play!ml detection you can see in the lower right corner is shown to you by Microsoft Defender. That anti-malware application is quite OK at scanning, however, prone to be basically unstable. It is defenseless to malware invasions, it has a glitchy user interface and problematic malware removal features. For this reason, the pop-up which states about the Play!ml is just a notification that Defender has detected it. To remove it, you will likely need to use another anti-malware program.

Ransom:Win32/Play!ml found

Microsoft Defender: “Ransom:Win32/Play!ml”

The exact Ransom:Win32/Play!ml virus is a very unpleasant thing. It sits into your computer under the guise of something legit, or as a part of the tool you downloaded from a forum. After that, it makes all possible steps to weaken your system. At the end of this “party”, it downloads other viruses – ones which are choosen by crooks who control this malware. Hence, it is likely impossible to predict the effects from Play!ml actions. And the unpredictability is one of the most upleasant things when it comes to malware. That’s why it is better not to choose at all, and don’t let the malware to complete its task.

Threat Summary:

NamePlay!ml Ransom
DetectionRansom:Win32/Play!ml
DetailsPlay!ml is attached to another program (such as a document), which can replicate and spread after an initial execution.
Fix ToolSee If Your System Has Been Affected by Play!ml Ransom

Behavior Analysis

Click to expand
  • Sample contains Overlay data;
  • Unconventionial language used in binary resources: Turkish;
  • The binary contains an unknown PE section name indicative of packing;
  • The binary likely contains encrypted or compressed data.;
  • Authenticode signature is invalid;
  • Anomalous binary characteristics;
  • Encrypting the documents kept on the target’s disk — so the victim cannot use these documents;
  • Blocking the launching of .exe files of anti-virus programs
  • Blocking the launching of installation files of anti-malware apps

File Info

Click to expand
name: 2F654677D69BCE8A7D4E.mlw
path: /opt/CAPEv2/storage/binaries/98d8a7948bfdea381e503f0ac4c1bc5948b83b2caac77137577d402333dfb1bf
crc32: BEBEA24B
md5: 2f654677d69bce8a7d4e18eca2a924f6
sha1: 27b0c9f6dec429419bc788ac16d00ea9e790f795
sha256: 98d8a7948bfdea381e503f0ac4c1bc5948b83b2caac77137577d402333dfb1bf
sha512: 0831045fd4559b5980f6a4202de80413bfc92728cf03814a44cf0a07d44d44ae1df6ae3673b4e2c2eacf9b316c9fc6d13919de4a555da9d2a7261377975310d2
ssdeep: 6144:nR/bxfnKkNuX1Ed5hZ9UxhX4O498sfti2QBm1vfN:nRzxvKCuedXrQ4984HQB6fN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1642412248AD39921F66B43F523343D7463AA2F306F4514EBAB9E3FB492B46D70406637
sha3_384: e8606d2142bad513336d8d71db232e0eb4ecde69612e8a72a50d17f90b27e7ea5a15076b4dfed886cd2e0476b01c4a94
ep_bytes: 5589e5e9cc370500006ac76a216800f8
timestamp: 2011-10-02 06:40:09

Version Info:

CompanyName: BitMefender S.R.L.
FileDescription: BitMefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: GUIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitMefender 2016
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Alternative Detection Names

Click to expand
BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGeneric.Dacic.A82088AB.A.537E1866
ClamAVWin.Trojan.Yakes-1870
FireEyeGeneric.mg.2f654677d69bce8a
CAT-QuickHealTrojan.GenericRI.S30222121
McAfeeGenericRXWD-RE!2F654677D69B
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1751349
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a60f61 )
AlibabaMalware:Win32/km_2eb30.None
K7GWTrojan ( 005a60f61 )
Cybereasonmalicious.7d69bc
BitDefenderThetaGen:NN.ZexaF.36318.ny1@a8TFxsiO
VirITTrojan.Win32.Generic.BDPN
CyrenW32/Zbot.OQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.RopProof.A suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Dacic.A82088AB.A.537E1866
NANO-AntivirusTrojan.Win32.Mlw.jxcsyq
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.kac
EmsisoftGeneric.Dacic.A82088AB.A.537E1866 (B)
BaiduWin32.Trojan.Kryptik.ej
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoader9.8340
VIPREGeneric.Dacic.A82088AB.A.537E1866
TrendMicroTSPY_ZBOT.SM3R
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataGeneric.Dacic.A82088AB.A.537E1866
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Yakes
ArcabitGeneric.Dacic.A82088AB.A.537E1866
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/Play!ml
GoogleDetected
AhnLab-V3Trojan/Win.Yakes.R582292
ALYacGeneric.Dacic.A82088AB.A.537E1866
TACHYONTrojan/W32.Agent.226413.C
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SM3R
RisingSpyware.Zbot!1.A1BA (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Yakes.dwnc
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

Is Ransom:Win32/Play!ml dangerous?

As I have actually mentioned , non-harmful malware does not exist. And Ransom:Win32/Play!ml is not an exclusion. This virus modifies the system configurations, edits the Group Policies and registry. All of these components are vital for correct system operating, even when we are not talking about PC safety. Therefore, the malware which Play!ml carries, or which it will download later, will squeeze out maximum profit from you. Cyber burglars can steal your personal information, and then push it at the black market. Using adware and browser hijacker functionality, built in Ransom:Win32/Play!ml malware, they can make revenue by showing you the advertisements. Each view gives them a penny, but 100 views per day = $1. 1000 victims who watch 100 banners per day – $1000. Easy math, but sad conclusions. It is a bad choice to be a donkey for crooks.

How did I get this virus?

It is not easy to trace the origins of malware on your computer. Nowadays, things are mixed up, and spreading tactics used by adware 5 years ago can be utilized by spyware these days. However, if we abstract from the exact spreading tactic and will think of why it works, the explanation will be quite uncomplicated – low level of cybersecurity knowledge. Individuals click on ads on weird websites, open the pop-ups they receive in their web browsers, call the “Microsoft tech support” assuming that the weird banner that states about malware is true. It is important to understand what is legitimate – to avoid misunderstandings when attempting to figure out a virus.

Microsoft tech support scam

The example of Microsoft Tech support scam banner

Nowadays, there are two of the most extensive tactics of malware distribution – bait e-mails and injection into a hacked program. While the first one is not so easy to avoid – you need to know a lot to understand a counterfeit – the 2nd one is easy to handle: just don’t use cracked programs. Torrent-trackers and various other providers of “free” applications (which are, in fact, paid, but with a disabled license checking) are just a giveaway place of malware. And Ransom:Win32/Play!ml is simply within them.

Remove Play!ml with Gridinsoft Anti-Malware

We have also been using this software on our systems ever since, and it has always been successful in detecting viruses. It has blocked the most common Ransoms as shown from our tests with the software, and we assure you that it can remove Play!ml as well as other malware hiding on your computer.

Gridinsoft Anti-Malware - Main Screen

To use Gridinsoft for remove malicious threats, follow the steps below:

1. Begin by downloading Gridinsoft Anti-Malware, accessible via the blue button below or directly from the official website gridinsoft.com.

2.Once the Gridinsoft setup file (setup-gridinsoft-fix.exe) is downloaded, execute it by clicking on the file.

setup-gridinsoft-fix.exe

3.Follow the installation setup wizard's instructions diligently.

Gridinsoft Setup Wizard

4. Access the "Scan Tab" on the application's start screen and launch a comprehensive "Full Scan" to examine your entire computer. This inclusive scan encompasses the memory, startup items, the registry, services, drivers, and all files, ensuring that it detects malware hidden in all possible locations.

Scan for Play!ml Ransoms

Be patient, as the scan duration depends on the number of files and your computer's hardware capabilities. Use this time to relax or attend to other tasks.

5. Upon completion, Anti-Malware will present a detailed report containing all the detected malicious items and threats on your PC.

The Play!ml was Found

6. Select all the identified items from the report and confidently click the "Clean Now" button. This action will safely remove the malicious files from your computer, transferring them to the secure quarantine zone of the anti-malware program to prevent any further harmful actions.

The Play!ml has been removed

8. If prompted, restart your computer to finalize the full system scan procedure. This step is crucial to ensure thorough removal of any remaining threats. After the restart, Gridinsoft Anti-Malware will open and display a message confirming the completion of the scan.

Remember Gridinsoft offers a 6-day free trial. This means you can take advantage of the trial period at no cost to experience the full benefits of the software and prevent any future malware infections on your system. Embrace this opportunity to fortify your computer's security without any financial commitment.

Trojan Killer for “Play!ml” removal on locked PC

In situations where it becomes impossible to download antivirus applications directly onto the infected computer due to malware blocking access to websites, an alternative solution is to utilize the Trojan Killer application.

Trojan Killer - Main View

There is a really little number of security tools that are able to be set up on the USB drives, and antiviruses that can do so in most cases require to obtain quite an expensive license. For this instance, I can recommend you to use another solution of GridinSoft - Trojan Killer Portable. It has a 14-days cost-free trial mode that offers the entire features of the paid version. This term will definitely be 100% enough to wipe malware out.

Trojan Killer is a valuable tool in your cybersecurity arsenal, helping you to effectively remove malware from infected computers. Now, we will walk you through the process of using Trojan Killer from a USB flash drive to scan and remove malware on an infected PC. Remember, always obtain permission to scan and remove malware from a computer that you do not own.

Step 1: Download & Install Trojan Killer on a Clean Computer:

1. Go to the official GridinSoft website (gridinsoft.com) and download Trojan Killer to a computer that is not infected.

Download Trojan Killer

2. Insert a USB flash drive into this computer.

3. Install Trojan Killer to the "removable drive" following the on-screen instructions.

Install Trojan Killer to Removable Drive

4. Once the installation is complete, launch Trojan Killer.

Step 2: Update Signature Databases:

5. After launching Trojan Killer, ensure that your computer is connected to the Internet.

6. Click "Update" icon to download the latest signature databases, which will ensure the tool can detect the most recent threats.

Click Update Button

Step 3: Scan the Infected PC:

7. Safely eject the USB flash drive from the clean computer.

8. Boot the infected computer to the Safe Mode.

9. Insert the USB flash drive.

10. Run tk.exe

11. Once the program is open, click on "Full Scan" to begin the malware scanning process.

Searching Play!ml Virus

Step 4: Remove Found Threats:

12. After the scan is complete, Trojan Killer will display a list of detected threats.

Searching Play!ml Finished

13. Click on "Cure PC!" to remove the identified malware from the infected PC.

14. Follow any additional on-screen prompts to complete the removal process.

Restart needed

Step 5: Restart Your Computer:

15. Once the threats are removed, click on "Restart PC" to reboot your computer.

16. Remove the USB flash drive from the infected computer.

Congratulations on effectively removing Play!ml and the concealed threats from your computer! You can now have peace of mind, knowing that they won't resurface again. Thanks to Gridinsoft's capabilities and commitment to cybersecurity, your system is now protected.

How to Remove Ransom:Win32/Play!ml Malware

Name: Ransom:Win32/Play!ml

Description: If you have seen a message showing the “Ransom:Win32/Play!ml found”, it seems that your system is in trouble. The Play!ml virus was detected, but to remove it, you need to use a security tool. Windows Defender, which has shown you this message, has detected the malware. However, Defender is not a reliable thing - it is prone to malfunction when it comes to malware removal. Getting the Ransom:Win32/Play!ml malware on your PC is an unpleasant thing, and removing it as soon as possible must be your primary task.

Operating System: Windows

Application Category: Ransom

Sending
User Review
4.35 (17 votes)
Comments Rating 0 (0 reviews)

About the author

Wilbur Woodham

I was a technical writer from early in my career, and consider IT Security one of my foundational skills. I’m sharing my experience here, and I hope you find it useful.

Leave a Reply

Sending