Malware

Should I remove “Troj/Agent-BFYM”?

Malware Removal

The Troj/Agent-BFYM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BFYM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Agent-BFYM?


File Info:

name: 7E4E1DB4338E4F8E3BD7.mlw
path: /opt/CAPEv2/storage/binaries/43dc8c047f80e4fbdc7bcc8a6791266488a30ee5ae60abd0d0f4fe2f70d9fde6
crc32: 04F32BC7
md5: 7e4e1db4338e4f8e3bd7b4ee2745fc54
sha1: 797b3b65aeeddebaf5fd3d3fcc88da6061724578
sha256: 43dc8c047f80e4fbdc7bcc8a6791266488a30ee5ae60abd0d0f4fe2f70d9fde6
sha512: a9b745eb9881978571b92ad88d55980f3764eb76fd8c55dc03aa8eb1d301f105a17c0398e23fac4ee9d46c4795c1a507f0bf338a3478ee4f5e06f7f73cbfa503
ssdeep: 12288:ByMriaMbz9Kdm/njCq3a05zPPnsuqzcVMFrg6CPdyuwUTj/T:oMGaw/neqK05UzcVqgbyYT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T137B412EF14068D49C87F04B240A7EB15BFBE06924D50A8759D8877E64BA8FA2F334539
sha3_384: 75fdb6ec6a7ca2ad98bb20a765c90392ac7d1902159b819d28b3d5e08de4c7b8e5998e6a1a9952a9433996f56331a241
ep_bytes: 60be6450dd7d81e98b79411909d981eb
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Troj/Agent-BFYM also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.576052
FireEyeGeneric.mg.7e4e1db4338e4f8e
McAfeeGenericRXAA-FA!7E4E1DB4338E
Cylanceunsafe
VIPREGen:Variant.Razy.576052
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057984e1 )
AlibabaTrojan:Win32/Injector.7f12efa3
K7GWTrojan ( 0057984e1 )
Cybereasonmalicious.4338e4
ArcabitTrojan.Razy.D8CA34
CyrenW32/S-91c2cc44!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.EBQH
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.576052
NANO-AntivirusTrojan.Win32.Razy.iecrjk
AvastWin32:Evo-gen [Trj]
RisingTrojan.Injector!1.C865 (CLASSIC)
SophosTroj/Agent-BFYM
DrWebTrojan.Inject4.12086
ZillyaTrojan.Injector.Win32.765417
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
EmsisoftGen:Variant.Razy.576052 (B)
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1200606
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Casur.A!cl
GDataGen:Variant.Razy.576052
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R263763
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36308.EmW@aG0ujDd
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallPAK_Xed-10
TencentWin32.Trojan.Generic.Xmhl
YandexTrojan.Injector!uxc0b7N2/EE
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.EBQH!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Agent-BFYM?

Troj/Agent-BFYM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment