Malware

Troj/Agent-BFUR removal instruction

Malware Removal

The Troj/Agent-BFUR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BFUR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Troj/Agent-BFUR?


File Info:

crc32: C10F3B7D
md5: 61a020506da81dd593b3c0519fec4fff
name: upload_file
sha1: d9d6dcd1f88fac63687781df7feb0e304ac125dd
sha256: 78dcacf7c79de953432bc37e2e8572f28611ba6cc9a69bdd7f4800bcea0c6939
sha512: 48ddc89ce98a1e3fb001c8563c0b05948a720a55603a1c87862f609c757d8612ac31f4b3439110403f67a2ebe9ab8e6c09a90f440988fe309d2f6479b234d6c1
ssdeep: 6144:GhKTKX20FgXOWBuNTjDJpa5qxLKnDfuMumtd7hyqSs5nxJQQhw8x52TveSGkAuC:Ghqy20yusjuAB4ZXun
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) 2000-2019 Martin Prikryl
CompanyName: Martin Prikryl
FileDescription: WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
ProductVersion: 5.15.2.0
ProductName: WinSCP
Translation: 0x0409 0x0514

Troj/Agent-BFUR also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.34822883
FireEyeGeneric.mg.61a020506da81dd5
CAT-QuickHealTrojan.Multi
McAfeeRDN/Generic BackDoor
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0019d9b81 )
BitDefenderTrojan.GenericKD.34822883
K7GWTrojan ( 0019d9b81 )
TrendMicroTROJ_FRS.0NA103JK20
CyrenW32/Kryptik.BKJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Agent.gen
AlibabaBackdoor:Win32/MortyStealer.79919319
ViRobotTrojan.Win32.Z.Agent.784896.V
Ad-AwareTrojan.GenericKD.34822883
SophosTroj/Agent-BFUR
ComodoMalware@#3j0txqcy8l1di
F-SecureTrojan.TR/AD.MortyStealer.ssylw
DrWebTrojan.PWS.Maria.4
ZillyaBackdoor.Agent.Win32.77912
InvinceaMal/Generic-R + Troj/Agent-BFUR
McAfee-GW-EditionBehavesLike.Win32.CryptDoma.bz
EmsisoftTrojan.GenericKD.34822883 (B)
JiangminTrojanDownloader.Generic.bccg
AviraTR/AD.MortyStealer.ssylw
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/Ymacco.AA78
ArcabitTrojan.Generic.D2135AE3
ZoneAlarmHEUR:Backdoor.Win32.Agent.gen
GDataTrojan.GenericKD.34822883
CynetMalicious (score: 90)
AhnLab-V3Malware/Win32.RL_Generic.R342422
BitDefenderThetaGen:NN.ZexaCO.34590.Vu0@auIieapi
ALYacTrojan.PSW.AveMaria
VBA32Backdoor.Agent
MalwarebytesBackdoor.AveMaria
PandaTrj/GdSda.A
ESET-NOD32Win32/Agent.TJS
TrendMicro-HouseCallTROJ_FRS.0NA103JK20
RisingTrojan.Agent!8.B1E (TFE:5:MxF43gI9uRQ)
YandexTrojan.Agent!nTNDRVV9Xq8
IkarusTrojan.Win32.Agent
FortinetW32/Agent.TJS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.6e0

How to remove Troj/Agent-BFUR?

Troj/Agent-BFUR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment