Trojan

Trojan:Win32/Bamital.E malicious file

Malware Removal

The Trojan:Win32/Bamital.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bamital.E virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Bamital.E?


File Info:

name: 09068DDAFB45D4C0C27D.mlw
path: /opt/CAPEv2/storage/binaries/179426827e4983bfdecce9e6cbffb379ef46acad162b0685b85e4ddb2a952be9
crc32: 23740224
md5: 09068ddafb45d4c0c27d764a34b792b3
sha1: 3c745899ee450f2428ca6b5f3371003eafa50010
sha256: 179426827e4983bfdecce9e6cbffb379ef46acad162b0685b85e4ddb2a952be9
sha512: 8e317cdd5cc24698ea2e1cb94095802fb730f7fe7543435b5e0d56395cb9f67b5c910ff5a21531adfa7ee1f81fcb9efbd3384c90a16c45e068a5808a235a7831
ssdeep: 768:q16hN7c8ux9FzsP0e4EW/Vad5Xq7L7+Noqb4rg4QIozAvaH6ubfoG6A4E:qwZnux9FzsPp4EW/Vad5Xq7LYErmXRaY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAF23C0AF13E4C77FC13167DABA27A75D262897CCC58D4306B2A629F951E7A136DC0C2
sha3_384: dd941b62ff26d5f282e23a0ad9dcf833e9ca5e0ac459071ae4a528a2ec3a4bfb7677ab5d1cc563ade8aa106a9a9eaf47
ep_bytes: 6a006a006a0068a89440006800010000
timestamp: 2010-05-19 21:12:38

Version Info:

0: [No Data]

Trojan:Win32/Bamital.E also known as:

LionicTrojan.Win32.Drooptroop.b!c
DrWebTrojan.MulDrop1.21059
MicroWorld-eScanTrojan.PWS.Kates.AA
FireEyeGeneric.mg.09068ddafb45d4c0
SkyhighBehavesLike.Win32.Dropper.nh
ALYacTrojan.PWS.Kates.AA
VIPRETrojan.PWS.Kates.AA
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00530fd91 )
BitDefenderTrojan.PWS.Kates.AA
K7GWTrojan ( 00530fd91 )
Cybereasonmalicious.9ee450
BitDefenderThetaAI:Packer.A83593061E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bamital.BS
APEXMalicious
KasperskyTrojan-Dropper.Win32.Drooptroop.bkm
AlibabaTrojanDropper:Win32/Bamital.b0f6557e
NANO-AntivirusTrojan.Win32.Drooptroop.bbneeq
RisingTrojan.Bamital!8.286 (TFE:3:4CBotX4Cn6K)
SophosMal/EncPk-PS
F-SecureTrojan.TR/Dropper.Gen2
ZillyaDropper.Drooptroop.Win32.5601
TrendMicroTROJ_BAMITAL.SMG
Trapminemalicious.high.ml.score
EmsisoftTrojan.PWS.Kates.AA (B)
IkarusTrojan-Dropper.Win32.Drooptroop
JiangminTrojanDropper.Drooptroop.cm
WebrootW32.Bamital.Gen
GoogleDetected
AviraTR/Dropper.Gen2
VaristW32/Bamital.B_b.gen!Eldorado
Antiy-AVLTrojan[Dropper]/Win32.Drooptroop
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Bamital.E
XcitiumTrojWare.Win32.TrojanDropper.DroopTroop.BALK@1qnk9k
ArcabitTrojan.PWS.Kates.AA
ZoneAlarmTrojan-Dropper.Win32.Drooptroop.bkm
GDataTrojan.PWS.Kates.AA
CynetMalicious (score: 100)
AhnLab-V3Dropper/Agent.36864.EG
McAfeeBackDoor-DKI.gen.dn
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.Inject.gen.2
Cylanceunsafe
PandaTrj/Dropper.JTA
TrendMicro-HouseCallTROJ_BAMITAL.SMG
TencentWin32.Trojan-Dropper.Drooptroop.Njgl
YandexTrojan.GenAsa!tqtfNc5xAA0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1278589.susgen
FortinetW32/Drooptroop.SMZ!tr
AVGWin32:Drooptroop [Drp]
AvastWin32:Drooptroop [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Bamital.E?

Trojan:Win32/Bamital.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment