Trojan

Should I remove “Dropped:Trojan.Bat.AAPW (B)”?

Malware Removal

The Dropped:Trojan.Bat.AAPW (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Bat.AAPW (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Dropped:Trojan.Bat.AAPW (B)?


File Info:

name: 89C991481E0704699FDC.mlw
path: /opt/CAPEv2/storage/binaries/5fc3460f399356fc782baf543fac89c489c6d955affb1a5c7d21fcc864047fba
crc32: B4A52783
md5: 89c991481e0704699fdcb14190067f44
sha1: e9b96f3e687146fa142ecfa5151506d71f928960
sha256: 5fc3460f399356fc782baf543fac89c489c6d955affb1a5c7d21fcc864047fba
sha512: 4c08a9f783e30762bd0dd7bd313bbe32ad337f82680df3609166202a915782b2de92e7cd1f2bff3ea84aa5456f41bf4cb09219b0c2e6ed6b99225a0470e990c4
ssdeep: 6144:ulcpdZcrWaQGVAF4GekXUcMnaOArINwdD6WkgWT4P3OpCq:JjkQGVi4GewOAEQD6WeD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12F242314403CDAA9D8723235D9044402A37ED61E2B025EE7EE1F68E26BD87F546FF298
sha3_384: 7ccca9ff1adc516ef481e6431be06275f2cf867df5b39390ce6f68a4ffcbb3f8eb0c1a1f19f5bfc0144b8fd6875afd6e
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2011-03-25 13:17:51

Version Info:

0: [No Data]

Dropped:Trojan.Bat.AAPW (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.42972
MicroWorld-eScanDropped:Trojan.Bat.AAPW
FireEyeGeneric.mg.89c991481e070469
CAT-QuickHealTrojan.GenericPMF.S17906421
ALYacDropped:Trojan.Bat.AAPW
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 00577de81 )
K7AntiVirusTrojan ( 005768dd1 )
BitDefenderThetaGen:NN.ZexaF.34114.Ry0@aSfE0Qb
CyrenW32/Dropper.EG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of BAT/Agent.NAS
TrendMicro-HouseCallTROJ_GEN.R002C0DGP21
ClamAVWin.Malware.Midie-9858153-0
KasperskyTrojan.BAT.Agent.bbn
BitDefenderDropped:Trojan.Bat.AAPW
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce3952
Ad-AwareDropped:Trojan.Bat.AAPW
SophosBat/Agent-BGKR
TrendMicroTROJ_GEN.R002C0DGP21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftDropped:Trojan.Bat.AAPW (B)
IkarusVirus.BAT.Agent
GDataDropped:Trojan.Bat.AAPW
JiangminTrojan.BAT.adj
eGambitUnsafe.AI_Score_99%
AviraTR/Redcap.osjdd
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.2A4BB41
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeGenericRXNM-EU!89C991481E07
VBA32Trojan.BAT.Agent
MalwarebytesTrojan.Dropper.BAT
APEXMalicious
RisingDropper.Agent!1.D197 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.F840!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.81e070

How to remove Dropped:Trojan.Bat.AAPW (B)?

Dropped:Trojan.Bat.AAPW (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment