Trojan

Trojan.Agent.BALW (B) malicious file

Malware Removal

The Trojan.Agent.BALW (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BALW (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.BALW (B)?


File Info:

name: D2FF9012D9B7EDD870B7.mlw
path: /opt/CAPEv2/storage/binaries/ef86f417cc9be4c77bcd9a3829ebbc1f915cb1b8a70eec404d0882c6e38e39d5
crc32: 31C2F96E
md5: d2ff9012d9b7edd870b71ec177df7729
sha1: 9ad33a135b6161f9f29a1a78e26b32c6de282ee3
sha256: ef86f417cc9be4c77bcd9a3829ebbc1f915cb1b8a70eec404d0882c6e38e39d5
sha512: da359b34ee33719bc6ab1cc55d14aba08b5c67ceb34bd2c3a0fb598b283e84742d374dafe800da77becc8d83701a87d8fb0031fe84b473982a0783de00a7da5e
ssdeep: 768:quVbxjgQNQXtckstOOtEvwDpjAaDOK6PsED3VK2+ZtyOjgO4r9vFAg2rq6W1A1PI:quJu9cvMOtEvwDpjWYTjipvF2bx1PQAI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19463D639BAD054B2E2B7867684F685D2B926BC627D61490F34CB334D4C33F52AC91E1E
sha3_384: da66cf07e7291c6e18678b99a666fa7765b3b06029a65cbc1cc959e4b9cb686825f2687a46eb3c2ffdef3d8cac5eb98d
ep_bytes: 60be009050008dbe0080ffff5783cdff
timestamp: 2013-10-02 12:59:11

Version Info:

0: [No Data]

Trojan.Agent.BALW (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.BALW
CAT-QuickHealTrojan.GenericRI.S28993524
SkyhighBehavesLike.Win32.PWSZbot.km
ALYacTrojan.Agent.BALW
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaDownloader.Small.Win32.233338
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0055c6c71 )
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
ArcabitTrojan.Agent.BALW
BaiduWin32.Trojan-Downloader.Small.c
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SMAG
ClamAVWin.Trojan.Zbot-64721
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BALW
NANO-AntivirusTrojan.Win32.DownLoad3.cjxpzu
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Agent-ASIV [Trj]
TencentTrojan-DL.Win32.Small.kf
TACHYONTrojan-Spy/W32.ZBot.71864
EmsisoftTrojan.Agent.BALW (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen2
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Agent.BALW
TrendMicroTROJ_UPATRE.SMAG
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.d2ff9012d9b7edd8
SophosTroj/Mdrop-FLP
IkarusTrojan.Win32.Agent
JiangminTrojanSpy.Zbot.eafz
GoogleDetected
AviraTR/Crypt.ULPM.Gen2
VaristW32/Small.AA.gen!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.U.Agent.27648[UPX]
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Malware/RL.Generic.R256208
Acronissuspicious
McAfeePWSZbot-FIA!869ECC5E7A6A
MAXmalware (ai score=82)
VBA32Trojan.Download
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!0NHD56KEAmA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Mdrop.AAB!tr
BitDefenderThetaGen:NN.ZexaF.36802.emNfaaO1D1ai
AVGWin32:Agent-ASIV [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Agent.BALW (B)?

Trojan.Agent.BALW (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment