Malware

Win32/RA-based.AB malicious file

Malware Removal

The Win32/RA-based.AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RA-based.AB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

bataysk.online

How to determine Win32/RA-based.AB?


File Info:

crc32: 4A46ACB6
md5: bc3583cf66b625033aa997d4946c8e67
name: BC3583CF66B625033AA997D4946C8E67.mlw
sha1: 76be32b1e10bb4b4afa8b5d2a67aedcf44bbbb07
sha256: f8db5ec2ebdcb50f3ac392ebbdef5783b9b55169b53d74f7b51bf566b08e4148
sha512: b1d7a3e841e7139c3918cfadcc13926a956637a29d942bf8a449fcad933da07065cba000904ce3dec6254f8d77c3bb5c9dcb834f8727ade9f80efcd7ed7f9766
ssdeep: 49152:QP3Mp+5fuO9j5zPw/rqsRikNZtgBSffBrd8xanCmLM7F2D7phGsta:kMp+HvPireUfoxDNm7p5ta
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/RA-based.AB also known as:

MicroWorld-eScanTrojan.GenericKD.12642455
FireEyeGeneric.mg.bc3583cf66b62503
ALYacTrojan.GenericKD.12642455
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004b9c221 )
BitDefenderTrojan.GenericKD.12642455
K7GWTrojan ( 004b9c221 )
Cybereasonmalicious.f66b62
ArcabitTrojan.Generic.DC0E897
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareTrojan.GenericKD.12642455
SophosMal/Generic-S
F-SecureTrojan.TR/Remoteadmin.tfcgf
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftTrojan.GenericKD.12642455 (B)
AviraTR/Remoteadmin.tfcgf
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.12642455
CynetMalicious (score: 100)
McAfeeArtemis!BC3583CF66B6
VBA32suspected of Trojan.Downloader.gen.h
PandaTrj/CI.A
ESET-NOD32Win32/RA-based.AB
TencentWin32.Trojan.Generic.Pgcr
SentinelOneStatic AI – Suspicious PE
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/RA-based.AB?

Win32/RA-based.AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment