Spy

Should I remove “ML/PE-A + W32/SennaSpy”?

Malware Removal

The ML/PE-A + W32/SennaSpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + W32/SennaSpy virus can do?

  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine ML/PE-A + W32/SennaSpy?


File Info:

name: 2D2A58358949C0DD4A50.mlw
path: /opt/CAPEv2/storage/binaries/980cf58bbf2bae97f90a79b613225328f682e1cf806a9d027caf9ab9275dade5
crc32: 0806D797
md5: 2d2a58358949c0dd4a50475e811e9dad
sha1: ba4d08905cb6a0feea8918ac8f7389a0ad97f856
sha256: 980cf58bbf2bae97f90a79b613225328f682e1cf806a9d027caf9ab9275dade5
sha512: 8282e23033006e69fae31db6c64b0a4ece272ceefe91432024b5a9a7044cf5ce70b8e370cab45303b84ffa2dab8fc410104859fbd6378063170ca79290d1f69e
ssdeep: 1536:IJvJnBpwdaMIOOnToIfiV6pdQ+2BUwOF7KrV3TVo1e:IJvxKaCqTBfiooytF7KrVJo1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BA38E177AC10963DCF2063001DA9A1ACB7BFD30073695A7E74F6FEA1B2169199352CB
sha3_384: 126178f07ea4513340fc061e770f5566b6a7043c53e4bbebb7722e1060ebcfd6e75f16460d1daa44af6875c5b9d72ad7
ep_bytes: 558bec6aff6800514100687419410064
timestamp: 2008-05-31 04:52:45

Version Info:

0: [No Data]

ML/PE-A + W32/SennaSpy also known as:

BkavW32.FamVT.RelocationResur.PE
MicroWorld-eScanWin32.Resur.B
FireEyeGeneric.mg.2d2a58358949c0dd
CAT-QuickHealW32.Resur
ALYacWin32.Resur.B
CylanceUnsafe
K7AntiVirusVirus ( 0040f51e1 )
K7GWVirus ( 0040f51e1 )
Cybereasonmalicious.58949c
ArcabitWin32.Resur.B
BaiduWin32.Virus.Resur.a
CyrenW32/Resurrect.B
SymantecW32.Resure.38400
Elasticmalicious (high confidence)
ESET-NOD32Win32/Resur.B
APEXMalicious
ClamAVWin.Virus.Resur-7001272-0
KasperskyVirus.Win32.Resur.e
BitDefenderWin32.Resur.B
NANO-AntivirusVirus.Win32.Resur.ccfj
AvastWin32:Resurrection
TencentVirus.Win32.Resur.gef
Ad-AwareWin32.Resur.B
SophosML/PE-A + W32/SennaSpy
ComodoVirus.Win32.Resur.a@4xmlyr
F-SecureMalware.W32/Resur.b
DrWebWin32.Senna.5
ZillyaVirus.Resur.Win32.1
TrendMicroPE_RESUR.B
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cm
EmsisoftWin32.Resur.B (B)
SentinelOneStatic AI – Suspicious PE
JiangminWin32/Resur.b
AviraW32/Resur.b
MicrosoftVirus:Win32/Resur.A!epo
ZoneAlarmVirus.Win32.Resur.e
GDataWin32.Resur.B
CynetMalicious (score: 100)
AhnLab-V3Win32/Resur.X983
McAfeeW32/Resur.b
MAXmalware (ai score=88)
VBA32Virus.Win32.Resur.f
MalwarebytesMalware.AI.4182470035
TrendMicro-HouseCallPE_RESUR.B
RisingVirus.Resur!1.D2CF (CLASSIC)
YandexWin32.Resur.F
MaxSecureVirus.W32.Resur.B
FortinetW32/Resurrect.B
BitDefenderThetaAI:FileInfector.9694FB900D
AVGWin32:Resurrection
PandaW32/Resur.B
CrowdStrikewin/malicious_confidence_60% (D)

How to remove ML/PE-A + W32/SennaSpy?

ML/PE-A + W32/SennaSpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment