Malware

About “BAT/Agent.PLI” infection

Malware Removal

The BAT/Agent.PLI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Agent.PLI virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Appears to use command line obfuscation
  • Powershell arguments were seen on a command line but powershell.exe was not called. Likely indictive of renamed/obfuscated powershell.exe or defining arguments in variables for later use
  • Uses suspicious command line tools or Windows utilities

How to determine BAT/Agent.PLI?


File Info:

name: 2F6491B72DD5DA951D5B.mlw
path: /opt/CAPEv2/storage/binaries/009ef7acdb9a3a7ff2262e8531e5273f307528a1e98ba61d6c0eb7117fbb1ae5
crc32: 3960534E
md5: 2f6491b72dd5da951d5bc1605377c42a
sha1: 8f64dddd4c6879e3340766c9c833a57e72ac3077
sha256: 009ef7acdb9a3a7ff2262e8531e5273f307528a1e98ba61d6c0eb7117fbb1ae5
sha512: 4bf3e9cffe60b42893d477b20eb4801a5bd8e8786631a498abe69185e1f57b0f7ae7a99e769b50626610ea9435b4699c26dd8d58ff084f4744bb042094dd3179
ssdeep: 6144:fc0h522p3l04ZMSmIp3Uy28uhyqe/I3k1ajSDAY61Np4T:nhxp3lZnT9bDuaI3uQSDHwX4T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10654CF02B7D28472D57319366D39A721A97C7C204F39CA9FA7D40D2E9E311D0A626FB3
sha3_384: a1446059399054751264fb3d080e201656160c1e68b24f5f91f0891b1c050c006393151535388e2492142a4052fcdf02
ep_bytes: e899040000e980feffff3b0db8914300
timestamp: 2016-08-14 19:15:49

Version Info:

0: [No Data]

BAT/Agent.PLI also known as:

BkavW32.AIDetect.malware2
CylanceUnsafe
K7AntiVirusTrojan ( 00593d421 )
CrowdStrikewin/malicious_confidence_100% (W)
Elasticmalicious (moderate confidence)
ESET-NOD32BAT/Agent.PLI
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.DcRat.eg
NANO-AntivirusTrojan.Win32.DcRat.jsykcw
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Dcrat.Kzfl
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.dh
SophosMal/Generic-S (PUA)
AviraBAT/Agent.axzaw
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!2F6491B72DD5
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen

How to remove BAT/Agent.PLI?

BAT/Agent.PLI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment