Malware

ML/PE-A + Mal/BcCheMan-A malicious file

Malware Removal

The ML/PE-A + Mal/BcCheMan-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/BcCheMan-A virus can do?

  • Unconventionial language used in binary resources: Spanish (El Salvador)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine ML/PE-A + Mal/BcCheMan-A?


File Info:

crc32: B2E9500F
md5: 41ccc9e7b10fafa88aefb4d651444993
name: 41CCC9E7B10FAFA88AEFB4D651444993.mlw
sha1: d7eb887d3e065e98b6b8295044f4c45034fd0d6b
sha256: 154ed21d509282316bcafd73ca803a15aabe9c407676b805d6af3e2e4716d30a
sha512: 5f9a19074580ce2900a3e63dd08e7e2b9234f43898f543f56eb1b309c14ebcc26fb6d473dd909152b4bdf8f0b8a5c69becbcf1edfc5eb4ea1ef931a1fb0aee9a
ssdeep: 3072:iX19YdKe35tM33SqsbCZltRcEbm99P6tp3YkwQ2:a9YdKef6iqMCYEbm9MIk6
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2011 SENDTo All Rights Reserved
InternalName: SENDTo
FileVersion: 1.1.0.1
CompanyName: www.SENDTo.com
LegalTrademarks: SENDTo.com
Comments: SENDTo - Shell Ext Adder
ProductName: Shell Ext Adder
ProductVersion: 1.1.0.1
FileDescription: SENDTo
OriginalFilename: SENDTo.exe
Translation: 0x0409 0x04b0

ML/PE-A + Mal/BcCheMan-A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f1d41 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.NgrBot.42
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.34330562
CylanceUnsafe
ZillyaTrojan.Generic.Win32.515294
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/BcCheMan.db2b39e4
K7GWTrojan ( 0040f1d41 )
Cybereasonmalicious.7b10fa
SymantecTrojan.Ransomlock!g8
APEXMalicious
AvastSf:Crypt-EX [Trj]
ClamAVWin.Ransomware.Yakes-9825801-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.34330562
NANO-AntivirusTrojan.Win32.NgrBot.bbwzwu
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
MicroWorld-eScanTrojan.GenericKD.34330562
TencentMalware.Win32.Gencirc.114be2d2
Ad-AwareTrojan.GenericKD.34330562
SophosML/PE-A + Mal/BcCheMan-A
ComodoMalware@#x24rxgiv1ted
VIPREWorm.Win32.Dorkbot.i (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.41ccc9e7b10fafa8
EmsisoftTrojan.GenericKD.34330562 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.anqvj
Webrootnone
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/DorkBot.DU
ArcabitTrojan.Generic.D20BD7C2
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.34330562
AhnLab-V3Trojan/Win32.Ransomlock.R42840
Acronissuspicious
McAfeeRansom-ABD.gen.a
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Oop
MalwarebytesRansom.FileCryptor
PandaTrj/Agent.MIZ
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!ytk+N+uJWNU
IkarusTrojan.Win32.Tobfy
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/RANSOM.AAY!tr
AVGSf:Crypt-EX [Trj]
Qihoo-360Win32/Trojan.Generic.HgAASQkA

How to remove ML/PE-A + Mal/BcCheMan-A?

ML/PE-A + Mal/BcCheMan-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment