Trojan

Trojan.Agent.BFMV removal tips

Malware Removal

The Trojan.Agent.BFMV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BFMV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.BFMV?


File Info:

name: AD90E18C144C774D93B5.mlw
path: /opt/CAPEv2/storage/binaries/2ffbac8309ca954ba52090cc80b2606d387ac242456cb3a3c8024bb227207bf3
crc32: 6ACA2A80
md5: ad90e18c144c774d93b586688cbd417b
sha1: 78b8f9db4940b22cd48a40d068458ffead504cdf
sha256: 2ffbac8309ca954ba52090cc80b2606d387ac242456cb3a3c8024bb227207bf3
sha512: 1938c6917a89c343d5f1d5da9201c9dac9454cb1be0aaf745a173af57c8330b62f2f524bc1670f974286d48cc6b2877e17b4c9f341f597d47c9926e5359282c5
ssdeep: 768:lJly7VQJBIg9NSqriNxX+AvivdFrDwh08SaYPDglcfe7A+O2IBlZ8obPvdti8/da:lJo7VQDniNx+FdFrDwzlvAejTq4NoPR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA930916BBE44965E16A273521FAC3E197B3B8585F53428F614822BD2C73F006E7E783
sha3_384: cc0f2858bc1c405b58723f91fa521da4a812176db68ff9a6a9ce24de1e24f5a1513a5496542e003940d8411365cc27fa
ep_bytes: 68c4124000e8f0ffffff000000000000
timestamp: 2012-12-01 08:37:08

Version Info:

CompanyName: cuqhswb
ProductName: uoaadbak
FileVersion: 3.82
ProductVersion: 3.82
InternalName: bgsyrxr
OriginalFilename: bgsyrxr.exe

Trojan.Agent.BFMV also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.BFMV.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BFMV
FireEyeGeneric.mg.ad90e18c144c774d
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.nt
ALYacTrojan.Agent.BFMV
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Agent.BFMV
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 005684c41 )
BitDefenderTrojan.Agent.BFMV
K7GWEmailWorm ( 005684c41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36792.fm0@auKu8Qii
VirITTrojan.Win32.Generic.BWGT
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VBObfus.IB
APEXMalicious
KasperskyWorm.Win32.WBNA.ipa
AlibabaWorm:Win32/VBObfus.af546ce7
NANO-AntivirusTrojan.Win32.Beebone.cmtitv
RisingWorm.WBNA!8.321 (TFE:3:D8Zf55s4SnS)
TACHYONTrojan/W32.Agent.94208
SophosMal/SillyFDC-AC
BaiduWin32.Worm.Pronny.a
F-SecureTrojan.TR/Beebone.22115468
DrWebTrojan.DownLoader7.33670
TrendMicroTSPY_SELFDEL_BL132AD9.TOMC
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Agent.BFMV (B)
IkarusTrojan.Win32.SelfDel
JiangminTrojan/Selfdel.hed
GoogleDetected
AviraTR/Beebone.22115468
VaristW32/VB.HM.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftTrojanDownloader:Win32/Beebone.FN
XcitiumTrojWare.Win32.VBO.ynf@4sido4
ArcabitTrojan.Agent.BFMV
ZoneAlarmWorm.Win32.WBNA.ipa
GDataTrojan.Agent.BFMV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.SelfDel.R45077
McAfeeW32/Autorun.worm.rd
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32Trojan.SelfDel
Cylanceunsafe
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallTSPY_SELFDEL_BL132AD9.TOMC
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Selfdel.cly
FortinetW32/WBNA.IPA!worm
AVGWin32:VB-AFEZ [Trj]
Cybereasonmalicious.b4940b
AvastWin32:VB-AFEZ [Trj]

How to remove Trojan.Agent.BFMV?

Trojan.Agent.BFMV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment