Malware

BAT/Renamer.AJ removal guide

Malware Removal

The BAT/Renamer.AJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Renamer.AJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Possible use of forfiles utility with wildcard to potentially launch a utility
  • Creates a known STOP-Djvu ransomware decryption instruction / key file.

How to determine BAT/Renamer.AJ?


File Info:

name: 944ED46E33710BD81588.mlw
path: /opt/CAPEv2/storage/binaries/04019b2906b5f89fbf692e82a27354d95cd651b877df4fceabc583e215ce7673
crc32: 084F4706
md5: 944ed46e33710bd81588579f8e6cf747
sha1: 0779e9e032ad9508dcdafb538bae81a19b5ee25a
sha256: 04019b2906b5f89fbf692e82a27354d95cd651b877df4fceabc583e215ce7673
sha512: 3ce95efefddfe68f547c3e0d644f44787d6c06ff7f2a8e9915ccdca3e325e18e77933541e0ade467645f265aff909e25573f4e5a78d65f695a91b71fb2264406
ssdeep: 1536:j7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfGxV+:/q6+ouCpk2mpcWJ0r+QNTBfG/+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129937C41F3E242F7E9E10A7100A6712FE73666289724E8DBC34C3D829553AD59A7C3F9
sha3_384: c84c271147540ecb9a0b4b444b342155a594c1741593dab4e266906307fbd9a13890e9bd69cc97ceccfcd8ad7491f30d
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

BAT/Renamer.AJ also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.944ed46e33710bd8
McAfeeRDN/Generic.rp
CylanceUnsafe
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058e26a1 )
K7GWTrojan ( 0058e26a1 )
VirITTrojan.Win32.Genus.IHW
CyrenW32/Kryptik.FDM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Renamer.AJ
TrendMicro-HouseCallTROJ_GEN.R002C0PB922
Paloaltogeneric.ml
KasperskyTrojan.Win32.Bingoml.dndh
AvastWin32:Malware-gen
SophosGeneric ML PUA (PUA)
TrendMicroTROJ_GEN.R002C0PB922
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_69%
Antiy-AVLTrojan/Win32.Tiggre
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmTrojan.Win32.Bingoml.dndh
CynetMalicious (score: 100)
Acronissuspicious
MalwarebytesMalware.AI.392946571
APEXMalicious
FortinetBAT/Renamer.AJ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.032ad9
PandaTrj/Genetic.gen

How to remove BAT/Renamer.AJ?

BAT/Renamer.AJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment