Malware

About “Mal/Generic-S + Troj/Agent-BFYB” infection

Malware Removal

The Mal/Generic-S + Troj/Agent-BFYB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Agent-BFYB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Mal/Generic-S + Troj/Agent-BFYB?


File Info:

name: E185D8FCB8A9967F606D.mlw
path: /opt/CAPEv2/storage/binaries/57850ff5d7326390225389f5777f87bd412057cc4c2f63ebf8aa8ce687e6f9f2
crc32: 67133705
md5: e185d8fcb8a9967f606d109c6a628f0d
sha1: 3f8e814c472908ec8b1cb1c7788630b2d139cc8e
sha256: 57850ff5d7326390225389f5777f87bd412057cc4c2f63ebf8aa8ce687e6f9f2
sha512: 9241c320f9e9b675d628a20b316f0544e708586f71fc7aa81a8c2faedcb092c010d24b73c4443ca76f0e0e702a2d9e266ff1f6a0afab04dbc58eb86e6a0936f5
ssdeep: 196608:0Cazg7DS8CazhCazg7DS8Cazg7DS8Caz8:Qg7u4hg7u4g7u48
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A286023AF5D08437D1236E7CCC5BA794A8357EE02D28608A7BE81D4D9F39B8135262D7
sha3_384: 18e44faad0513d7d26cad9e09a802449d46f2c152d470be5a5819af592fc8a8b1e4ddaf3238636fb11d82a66b5f39ee6
ep_bytes: 55545d906a2890596a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Mal/Generic-S + Troj/Agent-BFYB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7779
MicroWorld-eScanGen:Variant.Symmi.34741
FireEyeGeneric.mg.e185d8fcb8a9967f
CAT-QuickHealTrojan.WacatacPMF.S16539689
ALYacGen:Variant.Symmi.34741
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00548e051 )
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 00548e051 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.9896AD8521
CyrenW32/Injector.OZVT-2500
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AHHO
TrendMicro-HouseCallRansom_Blocker.R002C0DL621
ClamAVWin.Trojan.Mbrlock-9779766-0
KasperskyUDS:Trojan-Ransom.Win32.Blocker.vho
BitDefenderGen:Variant.Symmi.34741
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
AvastWin32:MBRlock-DV [Trj]
TencentTrojan.Win32.Blocker.zg
Ad-AwareGen:Variant.Symmi.34741
SophosMal/Generic-S + Troj/Agent-BFYB
ComodoTrojWare.Win32.Injector.HO@82j6jo
TrendMicroRansom_Blocker.R002C0DL621
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Symmi.34741 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.13Q4XMA
JiangminTrojan.Blocker.txd
MaxSecureTrojan.Malware.74696269.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.30ED84C
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Injector.INK!MTB
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Dapato.R83155
Acronissuspicious
McAfeeGenericRXIP-BJ!E185D8FCB8A9
MAXmalware (ai score=82)
VBA32Trojan.Downloader
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.DA56 (CLASSIC)
YandexTrojan.Injector!nfedw5apY3U
TACHYONRansom/W32.Blocker.7849472
eGambitUnsafe.AI_Score_89%
FortinetW32/Injector.AHHO!tr
AVGWin32:MBRlock-DV [Trj]
Cybereasonmalicious.cb8a99
PandaTrj/Genetic.gen

How to remove Mal/Generic-S + Troj/Agent-BFYB?

Mal/Generic-S + Troj/Agent-BFYB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment