Malware

Troj/Agent-BFJD removal tips

Malware Removal

The Troj/Agent-BFJD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BFJD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.intel.com
support.apple.com
help.twitter.com
soldkorean.top

How to determine Troj/Agent-BFJD?


File Info:

crc32: DFAFA3DC
md5: c25f5a4e5b16554c0607a1b16089a723
name: upload_file
sha1: f2501b3f2eb43725b6079f3a27c213aeaabd433a
sha256: 3517067834c67dfe59fc941b96ef30a24c946cf9d03e0ba3ef641a5031674b54
sha512: 1825e89d9a8b4d7506132b82c5d158952652eb2e3be09cd468314904b5fe380bbfe42e8ba5c4dbe5b1c0f9e4f9638624f82ec06aceb9ea3ba9f94755cb1e40d9
ssdeep: 1536:+ZJbgyeb0OiyK8D9fe2/kyb7ZOu4bPW5mP5CE3DgeiGzKqfDcHdapbTIB+pY4kUJ:SJbgrjKIXZfaBbUYJfDc0IB+pYvkQWFJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Crowd Instrument race xa9 2014
InternalName: Ago care Ship wish
FileVersion: 2.0.2.661
CompanyName: Root ReceiveWinter
ProductName: Cry.dll
ProductVersion: 2.0.2.661
FileDescription: Crowd Instrument race
Translation: 0x0409 0x04b0

Troj/Agent-BFJD also known as:

DrWebTrojan.IcedID.30
MicroWorld-eScanTrojan.GenericKD.34340795
FireEyeTrojan.GenericKD.34340795
Qihoo-360Win32/Trojan.d75
McAfeeGenericRXLQ-RN!C25F5A4E5B16
MalwarebytesTrojan.IcedID
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.34340795
K7GWTrojan ( 0056c5a81 )
K7AntiVirusTrojan ( 0056c5a81 )
BitDefenderThetaGen:NN.ZedlaF.34152.ku9@ayZxzWii
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.Cridex.qkv
AlibabaTrojanBanker:Win32/Cridex.336b88db
ViRobotTrojan.Win32.Z.Icedid.165378
AegisLabTrojan.Win32.Cridex.7!c
TencentWin32.Trojan-banker.Cridex.Swax
Ad-AwareTrojan.GenericKD.34340795
SophosTroj/Agent-BFJD
ComodoTrojWare.Win32.Agent.pwzuh@0
TrendMicroTROJ_GEN.R002C0DHC20
EmsisoftTrojan.GenericKD.34340795 (B)
AviraTR/AD.PhotoDlder.oaglp
FortinetW32/GenKryptik.EQDN!tr
ArcabitTrojan.Generic.D20BFFBB
ZoneAlarmTrojan-Banker.Win32.Cridex.qkv
MicrosoftTrojan:Win32/IcedId.DA!MTB
CynetMalicious (score: 85)
ALYacTrojan.IcedID.gen
MAXmalware (ai score=80)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EQDN
TrendMicro-HouseCallTROJ_GEN.R002C0DHC20
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan-Banker.IcedID
GDataTrojan.GenericKD.34340795
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Troj/Agent-BFJD?

Troj/Agent-BFJD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment