Malware

What is “Troj/Agent-BAFF”?

Malware Removal

The Troj/Agent-BAFF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BAFF virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Troj/Agent-BAFF?


File Info:

name: DC90484AE7F2C6740DEF.mlw
path: /opt/CAPEv2/storage/binaries/a3e4b6167c1fe19e34be5177f116806633bbd48c1128772b66fab7ac040f1a3d
crc32: 5384B60C
md5: dc90484ae7f2c6740def340e677d7a4f
sha1: c651d8bb8fe106c6ccd669d055547be1a1fb969e
sha256: a3e4b6167c1fe19e34be5177f116806633bbd48c1128772b66fab7ac040f1a3d
sha512: b1754b252d35b85804779d29c4a644480c28e9b6067dc394971d9db55b00cc0bae6e8bb899d96cb3e37f36a14eff22e550c5b91fc09d1eaf4da0a030dbe4fcf2
ssdeep: 12288:0XCNi9BwOdMvtSeedTyyryQYQfe/ctw43s1fLIN:fWCBePrHebLIN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3A412813E56D13BD42CA13F2B40EE7A8538E6B561308A83DF90D6186FADA72741C6D7
sha3_384: 7cffe18ce09dcddae77fe3efb23855fbb7952e51f845c32df9817a433a9534c68817060d58fba02b169ce804d30ca035
ep_bytes: 5589e56aff68dc18410068d85d400064
timestamp: 2006-03-02 17:50:37

Version Info:

0: [No Data]

Troj/Agent-BAFF also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Agent.tn3v
MicroWorld-eScanTrojan.GenericKDZ.94847
ClamAVWin.Malware.Eclz-9953021-0
McAfeeW32/Generic.worm.f
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.94847
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00008f2e1 )
AlibabaWorm:Win32/Agent.1222
K7GWTrojan ( 00008f2e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Agent.fj
CyrenW32/S-6bcd65fc!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Agent.cp
BitDefenderTrojan.GenericKDZ.94847
SUPERAntiSpywareWorm.Stone/Variant
AvastWin32:Agent-URR [Trj]
TencentWorm.Win32.Agent.d
EmsisoftTrojan.GenericKDZ.94847 (B)
DrWebWin32.HLLW.Siggen.1607
ZillyaWorm.Agent.Win32.9
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeTrojan.GenericKDZ.94847
SophosTroj/Agent-BAFF
IkarusTrojan.Crypt
GDataWin32.Worm.Sfone.B
JiangminWorm/Agent.ctm
Antiy-AVLWorm/Win32.Agent.cp
XcitiumWorm.Win32.Agent.CP@42tt
ArcabitTrojan.Generic.D1727F
ZoneAlarmWorm.Win32.Agent.cp
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Worm/Win32.Agent.R237442
ALYacTrojan.GenericKDZ.94847
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/CI.A
RisingWorm.Agent!1.CEBD (CLASSIC)
YandexWorm.Agent!5avxYeROPZ4
SentinelOneStatic AI – Malicious PE
MaxSecurePoly.Worm.Agent.CP
FortinetW32/Sfone.B!tr
AVGWin32:Agent-URR [Trj]
DeepInstinctMALICIOUS

How to remove Troj/Agent-BAFF?

Troj/Agent-BAFF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment