Malware

What is “BAT/Delwin.NAI”?

Malware Removal

The BAT/Delwin.NAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Delwin.NAI virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Detects the presence of Windows Defender AV emulator via files

How to determine BAT/Delwin.NAI?


File Info:

name: E1A581CE8D93875BD5C1.mlw
path: /opt/CAPEv2/storage/binaries/271499140cc37c89a0aa62181588dfb748b1f7ca1cd3ab8c8ee4301feb999657
crc32: A4FCC16B
md5: e1a581ce8d93875bd5c1c6db126816f3
sha1: f9d9e9f16759ad1b7d80039ed2db0ad6fee83ed5
sha256: 271499140cc37c89a0aa62181588dfb748b1f7ca1cd3ab8c8ee4301feb999657
sha512: 09171473855fc6f373c84582c3b475ae70ef20b655c1012e6555c4910f614f38e72ed6713133d063003c20cba7a8b65ecfcc275f894d6fac8d325073bf695bcb
ssdeep: 3072:i2sMWkzbJh1qZ9QW69hd1MMdxPe9N9uA0hu9TBfcX/t:DbJhs7QW69hd1MMdxPe9N9uA0hu9TBGt
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T147C33966B2E01198DBB581F6D9921706EB7074361B15A3DB6BB853B31B2B4C68F3C3D0
sha3_384: f8dd1822e2c9f1f826dd59d60261c006ff774af399b454865ca5d65b12bf254abe5b1ab0f00c0a45bdfd2e861371f335
ep_bytes: 4883ec2849c7c0600100004831d248b9
timestamp: 2018-02-01 19:43:24

Version Info:

0: [No Data]

BAT/Delwin.NAI also known as:

MicroWorld-eScanGen:Heur.Bat.1
FireEyeGeneric.mg.e1a581ce8d93875b
McAfeeArtemis!E1A581CE8D93
MalwarebytesTrojan.Agent
K7AntiVirusTrojan ( 0058b9991 )
AlibabaTrojan:BAT/Delwin.791051cd
K7GWTrojan ( 0058b9991 )
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/Delwin.NAI
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Heur.Bat.1
Ad-AwareGen:Heur.Bat.1
EmsisoftGen:Heur.Bat.1 (B)
McAfee-GW-EditionBehavesLike.Win64.Generic.ch
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Tiggre
GDataGen:Heur.Bat.1
AviraTR/Bat.Delwin.wmsgb
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Bat.1
ViRobotTrojan.Win32.Z.Bat.122368
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Heur.Bat.1
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.R002H09L821
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetBAT/Delwin.NAI!tr

How to remove BAT/Delwin.NAI?

BAT/Delwin.NAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment