Malware

How to remove “Troj/Agent-BFYM”?

Malware Removal

The Troj/Agent-BFYM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BFYM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Agent-BFYM?


File Info:

name: 4B4CF1A721540EF9E44E.mlw
path: /opt/CAPEv2/storage/binaries/b465c585a63de7c4db0dd3275c885e9ede4e6f3aa9c10a13a11e3b4cde00eaba
crc32: 10819D3F
md5: 4b4cf1a721540ef9e44e9695b79ceb2e
sha1: 496e15b0a2eeb5503b2d5d7025bb9fbc0db029a9
sha256: b465c585a63de7c4db0dd3275c885e9ede4e6f3aa9c10a13a11e3b4cde00eaba
sha512: 221ebf40df9cea3480f4295b87cd616d2cd0773942a4854270e992b51710d546755b8ed8530e2fbf34906d12c6ff0ac39691e40609d0f161f04bd80c9810362e
ssdeep: 12288:+YCPPB9nDAqFu8y0i61iKgiLwXnpyCIrpRawM6V:eh9nD9Q0iUiKnwXp+rp0zY
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AAB4126DDE67CAB9D77D08BE396275C5330043EF639260A469C6DD850422C283DCEAB6
sha3_384: 946483dd1af303e7521e77c5f773cd976f2c9946282915167d037463dcb947938cd5177d8166fabedb097d786daeaa63
ep_bytes: 60befe58624b81e9816694f689cabe00
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Troj/Agent-BFYM also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.576052
FireEyeGeneric.mg.4b4cf1a721540ef9
ALYacGen:Variant.Razy.576052
MalwarebytesMalware.Heuristic.1003
VIPREGen:Variant.Razy.576052
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057984e1 )
AlibabaTrojan:Win32/Injector.066d7f67
K7GWTrojan ( 0057984e1 )
Cybereasonmalicious.721540
CyrenW32/S-91c2cc44!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.EBQH
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.576052
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Cplw
SophosTroj/Agent-BFYM
DrWebTrojan.Inject4.12086
ZillyaTrojan.Injector.Win32.793742
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
EmsisoftGen:Variant.Razy.576052 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.576052
JiangminTrojan.Generic.goxci
AviraHEUR/AGEN.1200606
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Razy.D8CA34
MicrosoftTrojan:Win32/Ymacco.AAB4
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R263763
Acronissuspicious
McAfeeGenericRXMW-WO!4B4CF1A72154
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
TrendMicro-HouseCallPAK_Xed-10
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Agent!9r+5XXLvr/g
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EBQH!tr
BitDefenderThetaGen:NN.ZexaF.36308.EmW@aa@cnPk
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Agent-BFYM?

Troj/Agent-BFYM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment