Malware

About “BAT/RA-based.FY” infection

Malware Removal

The BAT/RA-based.FY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/RA-based.FY virus can do?

  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Modifies system policies to prevent the launching of specific applications or executables
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify UAC prompt behavior
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
stcubegames.netxi.in
iplogger.org

How to determine BAT/RA-based.FY?


File Info:

crc32: 63B37613
md5: d77446899ec960168998d49c55ffc9b6
name: test2.rar
sha1: 4420eb6533b96c6c5da888f2c29436a57891d26f
sha256: d6603a386e267eacd99612af431cc7cfef8cbf9b51ce4d3b8680dcdc7924ccc7
sha512: 22d574c1e1cb21634779b7822da031d8ae066ef99db88bc66a3a67b8b3fc0356b8d65530c41aeb400ae8106b2149b13e7ebbe3d859da8f2dc1d008537227bd34
ssdeep: 196608:4j1WZWkIH9FoALaYvcSAykwiwGPKFFR78LFzLLQG:4cZWkML0hy/FnIL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

BAT/RA-based.FY also known as:

DrWebVBS.Dropper.225
MicroWorld-eScanTrojan.GenericKD.42684127
FireEyeGeneric.mg.d77446899ec96016
CAT-QuickHealTrojan.VBS
Qihoo-360Generic/Trojan.8c1
McAfeeArtemis!D77446899EC9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.VBS.Agent.4!c
SangforMalware
K7AntiVirusTrojan ( 0053caee1 )
BitDefenderTrojan.GenericKD.42684127
K7GWTrojan ( 0053caee1 )
Cybereasonmalicious.99ec96
TrendMicroTROJ_GEN.R002C0DAC20
BitDefenderThetaAI:Packer.9E33D48C17
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-7546250-0
GDataTrojan.GenericKD.42684127
KasperskyTrojan.VBS.Agent.ajg
AlibabaTrojanPSW:Win32/Autoit.67e425cb
NANO-AntivirusTrojan.Win32.RAbased.fpopic
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrhlUB1LIL2k4VC4tMeE4UB)
Ad-AwareTrojan.GenericKD.42684127
EmsisoftTrojan.GenericKD.42684127 (B)
ComodoMalware@#2cty3kdate5jh
F-SecureHeuristic.HEUR/AGEN.1043766
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.rc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
CyrenW32/Trojan.WSIV-2335
AviraBAT/Rabased.xgaji
Antiy-AVLTrojan[Ransom]/Win32.Blocker
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28B4EDF
ZoneAlarmTrojan.VBS.Agent.ajg
MicrosoftTrojan:Win32/Occamy.C
ALYacTrojan.GenericKD.42684127
MAXmalware (ai score=86)
VBA32Trojan.VBS.Agent
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
ESET-NOD32BAT/RA-based.FY
TrendMicro-HouseCallTROJ_GEN.R002C0DAC20
TencentVbs.Trojan.Agent.Wrqa
IkarusTrojan-Spy.Azorult
eGambitUnsafe.AI_Score_91%
FortinetW32/PSW.DELF.OSF!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove BAT/RA-based.FY?

BAT/RA-based.FY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment