Trojan

TrojanDropper.BAT.Agent removal tips

Malware Removal

The TrojanDropper.BAT.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper.BAT.Agent virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

Related domains:

wpad.local-net

How to determine TrojanDropper.BAT.Agent?


File Info:

name: 8934FFAC949267368D6A.mlw
path: /opt/CAPEv2/storage/binaries/22def891888bee30cd3e8df51ed062ba2cb5b351bb5fd47c652347e9b2328e06
crc32: 3C66DD3A
md5: 8934ffac949267368d6a9fbba0e16df3
sha1: 2365455e1a332cc70e82fba6d94769f7a9d175e6
sha256: 22def891888bee30cd3e8df51ed062ba2cb5b351bb5fd47c652347e9b2328e06
sha512: 6259b3f5eb35dfe5f8b9522c40b24fadd6ad30fbf2a1fb9b941da9701bf30cd2f6d2fe779ed42188650b85d4bbb41a691636f8b88b7b436ef7f25d49026325a6
ssdeep: 49152:88Qjo/g81n2MHqFMrlTXqVU/gMiqBnckl24b:88Qjo/g87XN4dkf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E7502023AD5C2FDDE332971D64A3EB340A4FA684609684F73C6860C5FFAB81D527B95
sha3_384: b5a33d568dc94fb022909952d9a54c4e98e6781d6f4030529434bf49692f21bc9ce5e37b5dd78f64d090d6010aeb618b
ep_bytes: 558bec6aff689092410068cc67410064
timestamp: 2016-10-04 15:12:31

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 16.04
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2016 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 16.04
Translation: 0x0409 0x04b0

TrojanDropper.BAT.Agent also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47479310
FireEyeGeneric.mg.8934ffac94926736
CAT-QuickHealScript.Trojan.44879
McAfeePolyPatch-UPX
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderTrojan.GenericKD.47479310
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.e1a332
ArcabitTrojan.Generic.D2D47A0E
CyrenBAT/Downldr.AF
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DKN21
Paloaltogeneric.ml
KasperskyTrojan-Dropper.BAT.Agent.dv
AlibabaMalware:Win32/km_284054.None
Ad-AwareTrojan.GenericKD.47479310
EmsisoftTrojan.GenericKD.47479310 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebBAT.DownLoader.648
TrendMicroTROJ_GEN.R002C0DKN21
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
AviraTR/Dldr.Agent.gzslb
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.47479310
CynetMalicious (score: 99)
Acronissuspicious
ALYacTrojan.GenericKD.47479310
MAXmalware (ai score=95)
VBA32TrojanDropper.BAT.Agent
MalwarebytesMalware.Heuristic.1003
FortinetW32/PolyPatch.UPX!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove TrojanDropper.BAT.Agent?

TrojanDropper.BAT.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment