Malware

BAT/RA-based.CX information

Malware Removal

The BAT/RA-based.CX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/RA-based.CX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:5650, :0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
rmansys.ru

How to determine BAT/RA-based.CX?


File Info:

crc32: 730A7819
md5: 29a0fb42c31ec455aab5bfd76c20418b
name: 9219490d227f691c.exe
sha1: 5110b413904369d27ee6e71bca4aa0d1452cf042
sha256: 4937273be0ef7ba04cc76c9be306cf965d9574bab855be9988334f7969083798
sha512: ad0d0808a886c934f52b20341c25a662a2cb8328ffb0a04aae05e6631a8d55a25372fc3f999b6bebc952ed028e24ce84489246828ff3b302e0d210cd04c6ba00
ssdeep: 98304:g39YFcTEfSXfXjawNeqVLMxUFhPGXT431LsNMxqe:gWcTEYxeywU/PudOYe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BAT/RA-based.CX also known as:

MicroWorld-eScanGeneric.Remas.1.BCA51072
CAT-QuickHealHackTool.Rabased
McAfeeArtemis!29A0FB42C31E
VIPRETrojan.Win32.Generic!BT
K7GWUnwanted-Program ( 004bb5201 )
K7AntiVirusUnwanted-Program ( 004bb5201 )
TrendMicroTROJ_GE.01956262
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9999
SymantecTrojan.Gen.2
ESET-NOD32BAT/RA-based.CX
TrendMicro-HouseCallTROJ_GE.01956262
ClamAVWin.Malware.Agent-6365383-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Remas.1.BCA51072
NANO-AntivirusTrojan.Script.RMS.enpelx
SophosRemote Manipulator System (PUA)
ComodoTrojWare.Win32.Generic.usubc
F-SecureGeneric.Remas.1.BCA51072
DrWebBackDoor.RMS.82
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.rc
EmsisoftGeneric.Remas.1.BCA51072 (B)
SentinelOnestatic engine – malicious
CyrenTrojan.CULP-1
JiangminRemoteAdmin.RMS.w
AviraBDS/Backdoor.Gen2
FortinetWM/Moat.84AAD2A4!tr
Antiy-AVLRiskWare[RemoteAdmin]/Win32.RMS
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D263D48C
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftHackTool:Win32/Rabased
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=81)
VBA32Backdoor.RMS
MalwarebytesRiskWare.RemoteAdmin
PandaTrj/CI.A
YandexTrojan.InstallRadmin.B
IkarusTrojan.BAT.RA
GDataWin32.Riskware.RemoteAdmin.E
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.2c31ec
AvastWin32:PUP-gen [PUP]
CrowdStrikemalicious_confidence_90% (D)
Qihoo-360Win32/Backdoor.faa

How to remove BAT/RA-based.CX?

BAT/RA-based.CX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment