Trojan

Trojan.MicroBat removal guide

Malware Removal

The Trojan.MicroBat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MicroBat virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.MicroBat?


File Info:

name: F74BD756AB93D663B0B4.mlw
path: /opt/CAPEv2/storage/binaries/2a875697c9eb37dd4b65e7cf2ffd84576c3e4a7ba74c4698cbcbe869ce143c41
crc32: 6A2F40CA
md5: f74bd756ab93d663b0b42106a4094ae5
sha1: 1546a39dda816786dc75982c82b8c65716a5f4bf
sha256: 2a875697c9eb37dd4b65e7cf2ffd84576c3e4a7ba74c4698cbcbe869ce143c41
sha512: 2168e82dfbfa1f61db0255233dd5a73f7b1bfce425cd1223510a8517dbc76fd0f2b37bbdc2cf9fec2612fe0ecb6832f56de1889980389a50d26aa3598a5a578a
ssdeep: 1536:seqF6B+cGhweUXFAznZa2PBwKrD8/Qq471bZhPCMwo6bPtOR:e++cxVFAlwKrDa47YXbPtM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1A3D004B080A137E4FF45F809676C65A6293F2A4557A18B77E13C1D2AF1EAD8C21F6F
sha3_384: 3a5e1d70652af0a5651fd74fb83cf60f56c26c016dabf29e24b96822ffc9b1ff87b80bf1fa743316b08106ca3e4feac4
ep_bytes: 33d2ff742410e881ffffff59ff25a050
timestamp: 2002-03-16 07:21:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Run Once Wrapper
FileVersion: 6.00.3790.3959 (srv03_sp2_rtm.070216-1710)
InternalName: RunOnce
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: RUNONCE.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.3790.3959
Translation: 0x0409 0x04b0

Trojan.MicroBat also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f74bd756ab93d663
CylanceUnsafe
ZillyaTrojan.Tepfer.Win32.18308
SangforTrojan.Win32.Cridex.atS
AlibabaTrojan:Win32/Kryptik.f39e5b37
K7GWHacktool ( 700007861 )
Cybereasonmalicious.6ab93d
VirITTrojan.Win32.Crypt.BBVH
SymantecDownloader.Ponik!gen1
ESET-NOD32a variant of Win32/Kryptik.APYC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Fareit-9934116-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Sinowal.Gen.1
NANO-AntivirusTrojan.Win32.Stealer.bcjkrf
SUPERAntiSpywareTrojan.Agent/Gen-Uniqr
MicroWorld-eScanTrojan.Sinowal.Gen.1
AvastWin32:Cridex-S [Trj]
TencentWin32.Trojan.Generic.Ecjz
Ad-AwareTrojan.Sinowal.Gen.1
SophosML/PE-A + Troj/Zbot-DCQ
ComodoTrojWare.Win32.Kryptik.AQNR@4sr19a
DrWebTrojan.PWS.Stealer.946
VIPRETrojan.Win32.Reveton.q (v)
TrendMicroTrojanSpy.Win32.FAREIT.UHBAZCLKM
McAfee-GW-EditionPWS-Zbot.gen.aqc
EmsisoftTrojan.Sinowal.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Sinowal.Gen.1
JiangminTrojan/PSW.Tepfer.szg
WebrootW32.Trojan.Gen
AviraTR/Injector.aen
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Tepfer
KingsoftWin32.PSWTroj.Tepfer.cp.(kcloud)
ArcabitTrojan.Sinowal.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Fareit
AhnLab-V3Trojan/Win32.Pwstealer.R45256
Acronissuspicious
McAfeePWS-Zbot.gen.aqc
VBA32BScope.Malware-Cryptor.Fareit.7112
MalwarebytesTrojan.MicroBat
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.UHBAZCLKM
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan-PWS.Multi
eGambitGeneric.Malware
FortinetW32/Bublik.AM!tr
AVGWin32:Cridex-S [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.MicroBat?

Trojan.MicroBat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment