Malware

Troj/Agent-BAYG removal instruction

Malware Removal

The Troj/Agent-BAYG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BAYG virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Troj/Agent-BAYG?


File Info:

name: 0C983C6AABB573469A6B.mlw
path: /opt/CAPEv2/storage/binaries/a7ef991b479b9001ed5f77f9b215b64c0eaaf21378e339243bc77766f2f7f5bf
crc32: 847B983B
md5: 0c983c6aabb573469a6bbef2b9740c11
sha1: a45082c15a66354595c5366073f4080735df0a28
sha256: a7ef991b479b9001ed5f77f9b215b64c0eaaf21378e339243bc77766f2f7f5bf
sha512: de1904653b52c23e07344643ff52f10edb44331460dd4bd3bdd469331e044c85e391d2f6c90e080d30a6fc6354d854dcbdb893286156d90b517556113b271f2e
ssdeep: 3072:7CaoAs101Pol0xPTM7mRCAdJSSxPUkl3VEMQTCk/dN92sdNhavtrVdewnAx3wmVb:7qDAwl0xPTMiR9JSSxPUKgdodH6gk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1D408137321CC51F1D097B6A2A5C374BAB09B5428F3C913FAECAD66BF706524E1E50A
sha3_384: e156046deed293b90e839c51c14b54ac2373a8831d12dabb035c58b1d0acdcb8a3a123ed8b29b524d26bafa2be84d14f
ep_bytes: e85bc20300e8b0a9030033c0c3909090
timestamp: 2015-01-28 13:36:24

Version Info:

0: [No Data]

Troj/Agent-BAYG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.tpzq
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74320
FireEyeTrojan.GenericKDZ.74320
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FFZL!0C983C6AABB5
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.QQPass.Win32.24502
SangforSuspicious.Win32.Save.a
K7AntiVirusPassword-Stealer ( 004b75691 )
AlibabaTrojan:Win32/QQPass.383
K7GWPassword-Stealer ( 004b75691 )
Cybereasonmalicious.15a663
VirITTrojan.Win32.Generic.ATOF
CyrenW32/S-cf9259cd!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.oetk
BitDefenderTrojan.GenericKDZ.74320
SUPERAntiSpywareTrojan.Agent/Gen-QQPass
AvastWin32:QQPass-WK [Trj]
TencentTrojan.Win32.Scar.16000124
SophosTroj/Agent-BAYG
BaiduWin32.Trojan-PSW.QQPass.af
F-SecureTrojan.TR/QQpass.ubzhp
DrWebTrojan.DownLoader12.31656
VIPRETrojan.GenericKDZ.74320
TrendMicroTROJ_SCAR_GA250340.UVPA
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftTrojan.GenericKDZ.74320 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.19CENXV
JiangminTrojan/Generic.bbckw
AviraTR/QQpass.ubzhp
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.QQPass.OWD@6l9bso
ArcabitTrojan.Generic.D12250
ZoneAlarmTrojan.Win32.Scar.oetk
MicrosoftTrojan:Win32/QQPass
AhnLab-V3Trojan/Win.Scar.R416160
Acronissuspicious
ALYacTrojan.GenericKDZ.74320
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SCAR_GA250340.UVPA
RisingStealer.QQPass!1.A658 (CLASSIC)
IkarusTrojan.Vundo
MaxSecureTrojan.Scar.OETK
FortinetW32/Scar.OETK!tr
AVGWin32:QQPass-WK [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Agent-BAYG?

Troj/Agent-BAYG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment