Malware

What is “Win32/Packed.BAT2EXE.H suspicious”?

Malware Removal

The Win32/Packed.BAT2EXE.H suspicious is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.BAT2EXE.H suspicious virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
cdn.discordapp.com
ocsp.digicert.com
www.epicgames.com
x.ss2.us

How to determine Win32/Packed.BAT2EXE.H suspicious?


File Info:

crc32: 7B0EB698
md5: 34be1d63b5125efbe71a4944ffe6f6d2
name: 34BE1D63B5125EFBE71A4944FFE6F6D2.mlw
sha1: 24bf29eb943b51011d943d56ca34d3c332cdf8dd
sha256: bf946275fdcfd2d3298b88d60a9344c2364e56c135833fbfe5395ab2376691c1
sha512: 2f872ba35d64a83c2ef4b1889e9ccf78bd205d5a5bc16d49d9c78a8dcbdada96ac6287ca120b6d0da2c8804f4c2645be31820b9875490ad0013a41ba3c014009
ssdeep: 6144:jldk1cWQRNTBXD6Tju8wE72QBt5csgEkl88uNnb/o/XRZ23QaeCqcaN7+/0JX:jcv0NTpD6Ttwgttjho/XR6eCqu0JX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Packed.BAT2EXE.H suspicious also known as:

LionicTrojan.Win32.Tiny.trFe
Elasticmalicious (high confidence)
ALYacTrojan.GenericKD.46068322
CylanceUnsafe
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/Generic.5cd50f86
Cybereasonmalicious.b943b5
CyrenW32/Trojan.UDYB-8749
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BAT2EXE.H suspicious
ZonerTrojan.Win32.85523
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Agent.mytzru
BitDefenderTrojan.GenericKD.46068322
MicroWorld-eScanTrojan.GenericKD.46068322
TencentWin32.Backdoor.Agent.Lkoc
Ad-AwareTrojan.GenericKD.46068322
SophosMal/Generic-S (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.dx
FireEyeGeneric.mg.34be1d63b5125efb
EmsisoftTrojan.GenericKD.46068322 (B)
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASMalwS.2B9EB3B
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmBackdoor.Win32.Agent.mytzru
GDataTrojan.GenericKD.46068322
AhnLab-V3Malware/Win.Generic.C4408024
Acronissuspicious
McAfeeRDN/Generic.dx
MAXmalware (ai score=86)
VBA32Backdoor.Agent
PandaTrj/CI.A
RisingTrojan.Generic@ML.88 (RDML:u5UcquJRrzBCw1DHUmLhRg)
YandexBackdoor.Agent!resCBFNLTyo
IkarusTrojan.SuspectCRC
FortinetPossibleThreat.PALLASNET.H
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Packed.BAT2EXE.H suspicious?

Win32/Packed.BAT2EXE.H suspicious removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment