Malware

Troj/Agent-BFJF malicious file

Malware Removal

The Troj/Agent-BFJF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BFJF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

www.intel.com
support.apple.com
help.twitter.com
soldkorean.top

How to determine Troj/Agent-BFJF?


File Info:

crc32: 8742EA04
md5: 65735d7935049aeed3be123310ff5d2b
name: upload_file
sha1: a00cc4541801df21dba31cd672bcd89ee7a0cddb
sha256: fe6c0de1471535fb2fabb167f7dd8eceb587ee9fb1a873afea30453719c2b80f
sha512: 1d41870cfcabe90d46cab5467b19aa675234fdb22f92740a199a0a3fd6d9bec63322b7fc5fcb490cc18c88999e7f797108d45fd15ce41b11847e3097a10d9d10
ssdeep: 1536:+ZJbgyeb0OiyK8D9fe2/kyb7ZOu4bPW5mP5CEEDgeiGzKqfDcHdapbTIB+pY4kUJ:SJbgrjKIXZfaBbtYJfDc0IB+pYvkQWFJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Crowd Instrument race xa9 2014
InternalName: Ago care Ship wish
FileVersion: 2.0.2.661
CompanyName: Root ReceiveWinter
ProductName: Cry.dll
ProductVersion: 2.0.2.661
FileDescription: Crowd Instrument race
Translation: 0x0409 0x04b0

Troj/Agent-BFJF also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43643802
FireEyeTrojan.GenericKD.43643802
McAfeeGenericRXLQ-RN!65735D793504
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.43643802
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.Cridex.qkv
AlibabaTrojanBanker:Win32/Cridex.82bb80dd
AegisLabTrojan.Win32.Cridex.7!c
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Ad-AwareTrojan.GenericKD.43643802
SophosTroj/Agent-BFJF
F-SecureTrojan.TR/AD.PhotoDlder.oaglp
DrWebTrojan.IcedID.30
TrendMicroTROJ_GEN.R002C0DHC20
FortinetW32/GenKryptik.EQDN!tr
EmsisoftTrojan.GenericKD.43643802 (B)
IkarusTrojan-Banker.IcedID
CyrenW32/Trojan.JICN-4140
AviraTR/AD.PhotoDlder.oaglp
MAXmalware (ai score=85)
ArcabitTrojan.Generic.D299F39A
ZoneAlarmTrojan-Banker.Win32.Cridex.qkv
MicrosoftTrojan:Win32/IcedId.DA!MTB
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZedlaF.34152.ku9@ayZxzWii
ALYacTrojan.IcedID.gen
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EQDN
TrendMicro-HouseCallTROJ_GEN.R002C0DHC20
TencentWin32.Trojan-banker.Cridex.Wofz
GDataTrojan.GenericKD.43643802
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.d75

How to remove Troj/Agent-BFJF?

Troj/Agent-BFJF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment