Trojan

Trojan.BAT.Disabler (file analysis)

Malware Removal

The Trojan.BAT.Disabler is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.BAT.Disabler virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Modifies boot configuration settings
  • Attempts to disable or modify the Run command from the Start menu and the New Task (Run) command from Task Manager
  • Attempts to disable Windows Defender
  • Attempts to disable Windows Defender logging
  • Attempts to remove Windows Defender from context menu
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.BAT.Disabler?


File Info:

name: E2FAD190E14AB2D1DB2A.mlw
path: /opt/CAPEv2/storage/binaries/42dfccc525fe8fbc5c131fc60f126ee097a29ac10302385e8d0cb72bd363b8cd
crc32: A6420656
md5: e2fad190e14ab2d1db2a7bac065a1950
sha1: 3d015ee1198811c43418582550221c32571c0018
sha256: 42dfccc525fe8fbc5c131fc60f126ee097a29ac10302385e8d0cb72bd363b8cd
sha512: 2b73d2b58a8be1165607dcf6e2669755317d40e32d03e339cd4391af896da15dcea53c442c54791e9b79355cac4fdf5d6c578f8643bacae722098a3b60de7b62
ssdeep: 6144:/ldk1cWQRNTBoAgjc1E29gocnA21RlsKn1hJKMBDT:/cv0NTepijcA21RlsIJ3v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B546DD1D38E4CD5FDA206B1C837AC192112EE29A2364D5E93EB796598F33D32433A47
sha3_384: 975875c0322506b481f27fcec3a44a6b85d1245dabc34a63bce96e3fcee747fac88ba48c75a4f73af509b255d7a329a8
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription: Fuck Windows defender
Translation: 0x0000 0x04e4

Trojan.BAT.Disabler also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.50273910
FireEyeGeneric.mg.e2fad190e14ab2d1
McAfeeRDN/Ransom
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056d70f1 )
AlibabaRansom:BAT/LockBit.d2f65a67
K7GWTrojan ( 0056d70f1 )
Cybereasonmalicious.119881
VirITTrojan.Win32.Genus.IHW
CyrenW32/Trojan.VFBA-8001
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/KillAV.NFF
APEXMalicious
KasperskyHEUR:Trojan.BAT.Disabler.gen
BitDefenderTrojan.GenericKD.50273910
AvastWin32:Trojan-gen
TencentWin32.Risk.Generic.Alsk
Ad-AwareTrojan.GenericKD.50273910
SophosMal/Generic-S
ZillyaTool.Lazagne.Win32.102
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.GenericKD.50273910 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.50273910
MAXmalware (ai score=89)
MicrosoftRansom:Win32/LockBit.PA!MTB
CynetMalicious (score: 100)
MalwarebytesMalware.AI.392946571
RisingTrojan.KillAV/BAT!8.13304 (CLOUD)
IkarusTrojan.BAT.KillAV
MaxSecureTrojan.Malware.300983.susgen
FortinetBAT/KillAV.NFF!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.BAT.Disabler?

Trojan.BAT.Disabler removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment