Trojan

Dropped:Trojan.Bat.AAPW removal instruction

Malware Removal

The Dropped:Trojan.Bat.AAPW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Bat.AAPW virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Dropped:Trojan.Bat.AAPW?


File Info:

name: 467E5460A2880885F7A8.mlw
path: /opt/CAPEv2/storage/binaries/d79567e487297beb04bd30b72f8eebdeeef1e863171ef74e2238788ab5789e5c
crc32: CD9E000C
md5: 467e5460a2880885f7a8b354c1a21c13
sha1: 2ad2ec6fc7e5dd267c22ad788ed49160bd4f7a4b
sha256: d79567e487297beb04bd30b72f8eebdeeef1e863171ef74e2238788ab5789e5c
sha512: a64ea8a9da3fdc2614427dea89dc55de679124d283d8e564955cc15a61bb89800094998c05e6766a9b243574bccc61f9056e720b9a56f9c3a3e5c0fd57bc2fc0
ssdeep: 6144:AlcpdZcrWD4IrmRn5JqCHJB8TAStzgFEtrDVyF3A2sr/IR/gqk1:jjh4Irq5JxETASe0+3AP/lqk1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11C241262C6BEDB65DD29933C190DD61F0663A09C00332D1C5F4758EB39AA795EA3E34C
sha3_384: f03dbd04833c8b8ad58a597ef274af3b4fee2848b314cba4a8d2e1c15aab2adacec3299f9460d2ab421e550772de55f0
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2011-03-25 13:17:51

Version Info:

0: [No Data]

Dropped:Trojan.Bat.AAPW also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.42972
MicroWorld-eScanDropped:Trojan.Bat.AAPW
FireEyeGeneric.mg.467e5460a2880885
CAT-QuickHealTrojan.GenericPMF.S17906421
ALYacDropped:Trojan.Bat.AAPW
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005768dd1 )
K7GWTrojan ( 00577de81 )
Cybereasonmalicious.0a2880
BitDefenderThetaGen:NN.ZexaF.34114.Ry0@aSfE0Qb
CyrenW32/Dropper.EG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of BAT/Agent.NAS
TrendMicro-HouseCallTROJ_GEN.R002C0DGP21
ClamAVWin.Malware.Midie-9858153-0
KasperskyTrojan.BAT.Agent.bbn
BitDefenderDropped:Trojan.Bat.AAPW
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce3952
Ad-AwareDropped:Trojan.Bat.AAPW
SophosBat/Agent-BGKR
TrendMicroTROJ_GEN.R002C0DGP21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftDropped:Trojan.Bat.AAPW (B)
IkarusVirus.BAT.Agent
GDataDropped:Trojan.Bat.AAPW
JiangminTrojan.BAT.adj
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Redcap.osjdd
Antiy-AVLTrojan/Generic.ASMalwS.2A4BB41
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeGenericRXNM-EU!467E5460A288
MAXmalware (ai score=83)
VBA32Trojan.BAT.Agent
MalwarebytesTrojan.Dropper.BAT
APEXMalicious
RisingDropper.Agent!1.D197 (CLASSIC)
YandexTrojan.Redcap!THEsY1TIYFg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.F840!tr
AVGWin32:Evo-gen [Susp]

How to remove Dropped:Trojan.Bat.AAPW?

Dropped:Trojan.Bat.AAPW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment