Malware

What is “Troj/Agent-BFYM”?

Malware Removal

The Troj/Agent-BFYM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BFYM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Agent-BFYM?


File Info:

name: 1179A6EA07C2C1FFD62C.mlw
path: /opt/CAPEv2/storage/binaries/929eac0547ae506e1018925124738ffccf57132dfe54129f48cf55a73009a5a1
crc32: 4C766A30
md5: 1179a6ea07c2c1ffd62c3fc21268d02e
sha1: c50c70602a7ef1f33299daa707876996423dfb6b
sha256: 929eac0547ae506e1018925124738ffccf57132dfe54129f48cf55a73009a5a1
sha512: 793261e7c5f574c7325d74c23b6cafed8543160f53591718dcea883b76dbe8bdc1ed434d593ed06ff2ddfa334ac87f61d4cc15ee32884caa786251a7208ef588
ssdeep: 12288:AWhLFO21a+OgwbtHHCTSML2uStiszFgxaY/h5BfHVgBH:rLFjI+OxJHXC2uShpqjDfHV+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F1B4232407D4A0E0FBBAD4351693C58D263EB48E3DD1677438B33A7657FA8506F0A6E1
sha3_384: fddf37fd94e9e1ede6b6147b2adb790f8a5e87a563b2363911a4686ded6afe48dae4d18c4c546f3f82df96bdc8288be9
ep_bytes: 60be323c208c21db81c019ac3b1db871
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Troj/Agent-BFYM also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.576052
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.a07c2c
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
AvastWin32:Evo-gen [Trj]
AlibabaTrojan:Win32/Injector.184f37ea
DrWebTrojan.DownLoader36.13649
SophosTroj/Agent-BFYM
AviraHEUR/AGEN.1200606
Antiy-AVLGrayWare/Win32.Kryptik.ffp
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R263763
TencentWin32.Trojan.Generic.Ckjl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EBQH!tr
AVGWin32:Evo-gen [Trj]
Paloaltogeneric.ml

How to remove Troj/Agent-BFYM?

Troj/Agent-BFYM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment