Backdoor

Backdoor.BAT.RA-based.an removal instruction

Malware Removal

The Backdoor.BAT.RA-based.an is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.BAT.RA-based.an virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:5650, :0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

rmansys.ru

How to determine Backdoor.BAT.RA-based.an?


File Info:

crc32: 8DC5508A
md5: 21e9fc2bb66da48d1cad9721382b5a62
name: 62763adbe657bd6b.exe
sha1: 637fd7ca67edea08a437e1dc2666fd89c92f0f6e
sha256: 35c064da2a0956bc9a6006f578ab80fe125b4f6356ba544cedba3f6ebc9ce399
sha512: 8169a144f95f22879492570749dc7eca232f16496b18c9ee3035c620c4d804b6e817d78e32199f8d8bf43ec97abf17a113e9005cbe94e8d00debe8e2afa1d130
ssdeep: 98304:mPB38RzYf0ML2x5tTDaLclizm7KQF1iEaGzMG:mqRzYI7Da4Ii7KQrLMG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.BAT.RA-based.an also known as:

MicroWorld-eScanTrojan.GenericKD.40202363
CAT-QuickHealHackTool.Rabased
McAfeeArtemis!21E9FC2BB66D
K7GWTrojan ( 005210ff1 )
K7AntiVirusTrojan ( 005210ff1 )
TrendMicroTROJ_GE.EFA6E417
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9999
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GE.EFA6E417
ClamAVWin.Malware.Agent-6365383-0
KasperskyBackdoor.BAT.RA-based.an
BitDefenderTrojan.GenericKD.40202363
NANO-AntivirusTrojan.Script.RMS.enpelx
Ad-AwareTrojan.GenericKD.40202363
SophosRemote Manipulator System (PUA)
F-SecureGeneric.Remas.1.384700D8
DrWebBAT.Starter.181
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.rc
EmsisoftTrojan.GenericKD.40202363 (B)
CyrenW32/Trojan.MBDS-0756
JiangminRemoteAdmin.RMS.w
AviraBAT/Disabler.puzra
Antiy-AVLRiskWare[RemoteAdmin]/Win32.RMS
MicrosoftHackTool:Win32/Rabased
Endgamemalicious (high confidence)
ZoneAlarmBackdoor.BAT.RA-based.an
GDataWin32.Riskware.RemoteAdmin.E
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=99)
VBA32Backdoor.RMS
MalwarebytesRiskWare.RemoteAdmin
PandaTrj/CI.A
ESET-NOD32BAT/RA-based.EC
TencentBat.Backdoor.Ra-based.Hrph
YandexTrojan.InstallRMS.C
SentinelOnestatic engine – malicious
FortinetWM/Moat.84AAD2A4!tr
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.bb66da
AvastWin32:PUP-gen [PUP]
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360Win32/Backdoor.c29

How to remove Backdoor.BAT.RA-based.an?

Backdoor.BAT.RA-based.an removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment