Worm

Worm:Win32/Bitab.A malicious file

Malware Removal

The Worm:Win32/Bitab.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Bitab.A virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Creates a copy of itself
  • Empties the Recycle Bin, indicative of ransomware
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Bitab.A?


File Info:

name: 1C172BCCC063D0B0FE01.mlw
path: /opt/CAPEv2/storage/binaries/165589aaa70d725572a764bf0a364a3b7b7b5634745e041c81e986faaa780ddc
crc32: C40D8143
md5: 1c172bccc063d0b0fe01e7db3c4a1049
sha1: c9d746d8022475f89128a946dd7246647840147a
sha256: 165589aaa70d725572a764bf0a364a3b7b7b5634745e041c81e986faaa780ddc
sha512: dbefb940667c754a3b920301230d10e89b1a73afe766d75a7cdef53c3ce06fd6d31391f2107da555e8c21b16d1163f56ca6c203e2e31cc00ca49f05e7880abd4
ssdeep: 3072:W8Ug4LrUb0a5lCIY6LDtCIY6LDwIyhGu:lUzrM0ahYaDbYaDwIyhj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADE66D7BE694C5B2E012D9BC5D16C2689B3672301D29C4F5FEA90DCDDDAD3D21A0C28B
sha3_384: 9fa74411ed65217ec6effada967878cb9e581ee28a5eb208825b7a22e42bde2952c7f757a0d8fd8af04066cf7fb5248b
ep_bytes: 558becb90b0000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Bitab.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lBJ1
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Doina.65073
FireEyeGeneric.mg.1c172bccc063d0b0
CAT-QuickHealMonitor.ActualSpy.11693
SkyhighPolyPatch-UPX
ALYacGen:Variant.Doina.65073
Cylanceunsafe
ZillyaTrojan.Agent.Win32.128080
SangforTrojan.Win32.Save.a
K7AntiVirusP2PWorm ( 000100931 )
AlibabaWorm:Win32/Bitab.382574d2
K7GWP2PWorm ( 000100931 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Doina.DFE31
BitDefenderThetaGen:NN.ZelphiF.36744.@pZ@aSRW1ieb
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.Delf.GX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.Agent.hy
BitDefenderGen:Variant.Doina.65073
NANO-AntivirusTrojan.Win32.Agent.cszaw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.HideProc.a
EmsisoftGen:Variant.Doina.65073 (B)
BaiduWin32.Trojan.Delf.it
F-SecureTrojan.TR/Autorun.12176358
DrWebTrojan.MulDrop3.3400
VIPREGen:Variant.Doina.65073
TrendMicroTSPY_MONITOR_CA0829E6.TOMC
Trapminemalicious.high.ml.score
SophosTroj/PWS-BJM
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Agent.hjs
AviraTR/Autorun.12176358
Antiy-AVLTrojan[GameThief]/Win32.Agent
KingsoftWin32.HeurC.KVM005.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftWorm:Win32/Bitab.A
ViRobotTrojan.Win32.PSWAgent.11349634
ZoneAlarmTrojan-GameThief.Win32.Agent.hy
GDataWin32.Trojan.PSE.1GV2BMY
VaristW32/Risk.FDXH-3788
AhnLab-V3Trojan/Win32.Agent.R88104
Acronissuspicious
McAfeePolyPatch-UPX
MAXmalware (ai score=100)
VBA32Trojan-GameThief.Agent
MalwarebytesDelphi.Worm.AutoRun.DDS
PandaGeneric Malware
TrendMicro-HouseCallTSPY_MONITOR_CA0829E6.TOMC
RisingTrojan.Win32.DelfCode.cq (CLOUD)
YandexTrojan.GenAsa!3JenvWvxSH0
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.1362840.susgen
FortinetW32/AutoRun.SUY!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.802247
DeepInstinctMALICIOUS

How to remove Worm:Win32/Bitab.A?

Worm:Win32/Bitab.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment