Categories: Trojan

Trojan.Agent.BALW (file analysis)

The Trojan.Agent.BALW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BALW virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Agent.BALW?


File Info:

crc32: 46D83ED9md5: ad1c154dc71a1dc518c991e882c7fcb0name: AD1C154DC71A1DC518C991E882C7FCB0.mlwsha1: 4438d2950b9130cd0608ee696ed6f35cf76a7277sha256: ab4a4a64a0dbf1f725682fdeeb21e02394aaff11c969b53abe859bc03df4f97asha512: f7bf9edf1ca8963b08f82bad555c15720103090a334cd5b3ed477a4996e60f5fcdec5f6cf2751850cbd825e11787dd6902221717286679656a4ceaa7abe06199ssdeep: 1536:P8mnK6QFElP6n+gymddpMOtEvwDpjYfKh6:1nK6a+qdOOtEvwDpjStype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Agent.BALW also known as:

K7AntiVirus Trojan ( 004bcce41 )
DrWeb Trojan.DownLoad3.28161
MicroWorld-eScan Trojan.Agent.BALW
ALYac Trojan.Agent.BALW
Cylance Unsafe
Zillya Trojan.Generic.Win32.937146
Sangfor Malware
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanDownloader:Win32/Upatre.cc48017a
K7GW Trojan ( 004bcce41 )
TrendMicro TROJ_GEN.R002C0DE620
Baidu Win32.Trojan-Downloader.Small.c
Cyren W32/Upatre.IL.gen!Eldorado
ESET-NOD32 Win32/TrojanDownloader.Small.AAB
Zoner Trojan.Win32.18796
APEX Malicious
Avast Win32:Agent-ASIV [Trj]
ClamAV Win.Trojan.Upatre-3337
GData Trojan.Agent.BALW
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.Agent.BALW
NANO-Antivirus Trojan.Win32.DownLoad3.cjxpzu
ViRobot Trojan.Win32.Z.Upatre.60012.X
SUPERAntiSpyware Trojan.Agent/Gen-Injector
Tencent Malware.Win32.Gencirc.10b49923
Ad-Aware Trojan.Agent.BALW
Sophos Troj/Mdrop-FLP
Comodo TrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
F-Secure Adware.ADWARE/Adware.Gen
BitDefenderTheta Gen:NN.ZexaF.34110.dq2@aKe2H9pi
VIPRE Trojan.Win32.Zbot.gxb (v)
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.qt
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.ad1c154dc71a1dc5
Emsisoft Trojan.Agent.BALW (B)
SentinelOne DFI – Malicious PE
F-Prot W32/Upatre.IL.gen!Eldorado
Endgame malicious (moderate confidence)
Webroot W32.Trojan.Gen
Avira ADWARE/Adware.Gen
Antiy-AVL Trojan/Win32.Agent
Microsoft TrojanDownloader:Win32/Upatre.A
Jiangmin TrojanSpy.Zbot.eafz
Arcabit Trojan.Agent.BALW
AegisLab Trojan.Win32.Zbot.lMmI
ZoneAlarm HEUR:Trojan.Win32.Generic
AhnLab-V3 Win-Trojan/Malpacked5.Gen
Acronis suspicious
McAfee GenericRXIH-CT!AD1C154DC71A
MAX malware (ai score=81)
VBA32 Trojan.Download
Malwarebytes Adware.IStartSurf
Panda Trj/Genetic.gen
TrendMicro-HouseCall TROJ_GEN.R002C0DE620
Rising Spyware.Zbot!8.16B (CLOUD)
Yandex Trojan.Agent!s/NvQFQStuQ
Ikarus Backdoor.Win32.Androm
MaxSecure Trojan.Upatre.Gen
Fortinet W32/Mdrop.AAB!tr
AVG Win32:Agent-ASIV [Trj]
Paloalto generic.ml
Qihoo-360 Win32/Trojan.93a

How to remove Trojan.Agent.BALW?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago