Malware

Troj/Agent-BEML removal instruction

Malware Removal

The Troj/Agent-BEML is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BEML virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Agent-BEML?


File Info:

name: E1E335C9219E9039C5ED.mlw
path: /opt/CAPEv2/storage/binaries/51a07a53c58ef5777471566634c46f2c3ede4c6359cd896f71922099e509d82f
crc32: 272204C6
md5: e1e335c9219e9039c5ed69b9b7411f6c
sha1: ad2f9d8af76e228a261e8b93725adcf704caac90
sha256: 51a07a53c58ef5777471566634c46f2c3ede4c6359cd896f71922099e509d82f
sha512: 15ef4f593d41afdf1f65bed206339a83150fceb421eb2c18502bbac422d309d18d722304369c0c39c236ac0a4994bafdbd69a912cd999cf293baaf5d5670c341
ssdeep: 1536:ur3Z5IfQmv81aZKyXXZPbihOjrqLy14Gp7FtnV7pjCCEPPPouuuuL:yJOfQm01KKyXXZPbi8aIp7nCCTuuuuL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA24DB3305F0188FC82EC6B029C72C7619376C358613FA5B9579B61A95B5A03EEE2CDD
sha3_384: 67f7533df5d00b74b12846a92426402d1df51a56e1d06602aad1ca601508be5debfcfa8ca32b056bca14fccc4841097c
ep_bytes: 558bec6aff687071400068c03a400064
timestamp: 2017-05-06 16:04:14

Version Info:

Comments:
CompanyName: Hello World
FileDescription: Clien Local RunProcess
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: hello.exe
LegalCopyright: All rights reserved.
LegalTrademarks:
OriginalFilename: Hello World
PrivateBuild:
ProductName: Hello Worl
:

Troj/Agent-BEML also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94849
ClamAVWin.Trojan.Nitol-6335025-0
FireEyeGeneric.mg.e1e335c9219e9039
CAT-QuickHealTrojan.Nitol.A
McAfeeGenericRXCU-PI!E1E335C9219E
MalwarebytesGeneric.Trojan.ServStart.DDS
ZillyaTrojan.ServStart.Win32.18524
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0054d1101 )
K7GWTrojan ( 0054d1101 )
Cybereasonmalicious.9219e9
ArcabitTrojan.Generic.D17281
BitDefenderThetaGen:NN.ZexaF.36196.nq3@aqaZQPij
CyrenW32/S-8871cb94!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/ServStart.RC
ZonerTrojan.Win32.123890
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-GameThief.Win32.Magania.gen
BitDefenderTrojan.GenericKDZ.94849
NANO-AntivirusTrojan.Win32.GenKryptik.fnpyle
AvastWin32:Nitol-B [Trj]
TencentTrojan.Win32.Nitol.wa
SophosTroj/Agent-BEML
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader24.55874
VIPRETrojan.GenericKDZ.94849
TrendMicroDDOS_NITOL.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.dz
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94849 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.daixb
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
MicrosoftDDoS:Win32/Nitol.B
ZoneAlarmHEUR:Trojan-DDoS.Win32.Nitol.gen
GDataWin32.Trojan.ServStart.F
GoogleDetected
AhnLab-V3Trojan/Win32.Nitol.R205727
VBA32BScope.Trojan.Downloader
ALYacTrojan.GenericKDZ.94849
MAXmalware (ai score=86)
Cylanceunsafe
TrendMicro-HouseCallDDOS_NITOL.SMC
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
IkarusTrojan.Win32.Agent
FortinetMalwThreat!E1E6IV
AVGWin32:Nitol-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Agent-BEML?

Troj/Agent-BEML removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment