Malware

About “ML/PE-A + Troj/Agent-BCMM” infection

Malware Removal

The ML/PE-A + Troj/Agent-BCMM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Agent-BCMM virus can do?

  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

dns-blabla.com
dns-blabla.net

How to determine ML/PE-A + Troj/Agent-BCMM?


File Info:

crc32: 3EA69F36
md5: 0763ab78cd2a83cc75666a5199505702
name: 0763AB78CD2A83CC75666A5199505702.mlw
sha1: 9e4d739ebebffdb909d867b60cec836b21ad6596
sha256: b5a1023acd89384e44bb9cdb96f6e3a48c7e55e4ec50554e73b826a99850f498
sha512: a5b9a616855ff5eda40125fa74e6d22e2b97a65fc81b4ec12e518ed0455eda90a719aedbbd980eb6e71a740611e948980943ed6cf5a23b1af950ab2b9418dab9
ssdeep: 12288:uK0MhHT2LPemnDLeeeeI+AeAILSFT+AJHuUpNkQheY6eeu+zpNHHu3:uK0Mhz2LPemDLeeeeEeAkSFtVuwkQheW
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

ML/PE-A + Troj/Agent-BCMM also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.EJ
FireEyeGeneric.mg.0763ab78cd2a83cc
CAT-QuickHealWorm.Socks.13494
McAfeeArtemis!0763AB78CD2A
CylanceUnsafe
VIPREP2P-Worm.Win32.Socks.g (fs)
AegisLabTrojan.Win32.Generic.l92u
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Crypt.EJ
K7GWEmailWorm ( 005662bd1 )
K7AntiVirusEmailWorm ( 005662bd1 )
BitDefenderThetaAI:Packer.B069DE271B
CyrenW32/Socks.A.gen!Eldorado
SymantecW32.Mandaph
ESET-NOD32a variant of Win32/Socks.NAJ
BaiduWin32.Trojan-PSW.Agent.b
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Socks-7363613-0
KasperskyTrojan-Ransom.Win32.Blocker.itys
AlibabaWorm:Win32/Blocker.2a2d35bf
NANO-AntivirusTrojan.Win32.Socks.lpxw
Ad-AwareTrojan.Crypt.EJ
SophosML/PE-A + Troj/Agent-BCMM
ComodoMalware@#2qocyh8kehah5
F-SecureTrojan.TR/Dldr.Agent.agl
DrWebTrojan.DownLoader.62773
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Backdoor.jc
EmsisoftTrojan.Crypt.EJ (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Socks.ni
MaxSecureWorm.Socks
AviraTR/Dldr.Agent.agl
Antiy-AVLWorm/Win32.Socks
MicrosoftWorm:Win32/Autorun.gen!BS
ArcabitTrojan.Crypt.EJ
AhnLab-V3Worm/Win32.Socks.R2364
ZoneAlarmTrojan-Ransom.Win32.Blocker.itys
GDataTrojan.Crypt.EJ
CynetMalicious (score: 100)
TotalDefenseWin32/Korced!generic
Acronissuspicious
VBA32SScope.Worm.Socks.afv
ALYacTrojan.Crypt.EJ
MAXmalware (ai score=81)
MalwarebytesGeneric.Worm.Autorun.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_SOCKS.BL
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!XFaKFzne070
IkarusTrojan-Downloader.Win32.Small
eGambitUnsafe.AI_Score_99%
FortinetW32/Socks.HF!worm
AVGWin32:Malware-gen
Cybereasonmalicious.8cd2a8
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwsBpTAA

How to remove ML/PE-A + Troj/Agent-BCMM?

ML/PE-A + Troj/Agent-BCMM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment