Trojan

How to remove “Trojan.Agent.BAVS”?

Malware Removal

The Trojan.Agent.BAVS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BAVS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Trojan.Agent.BAVS?


File Info:

name: FEE1D9EA4CB447DE2648.mlw
path: /opt/CAPEv2/storage/binaries/e6ecd737fd7c2511181b815657fcf6540f1c6a886c7ec2ace7ca1b6417af2169
crc32: D0CC5A5F
md5: fee1d9ea4cb447de2648060ee1dd4278
sha1: 7526647347dc93045c7df2dc77746172f32e23df
sha256: e6ecd737fd7c2511181b815657fcf6540f1c6a886c7ec2ace7ca1b6417af2169
sha512: 709cdb9c35d62be41a95f09e83e973c6d48015cf3fd42ec06ba335b773756eed23965d8f4ede9e606d57ef462e64f1b31aed6f3cdd002af86be2dc68d33b895c
ssdeep: 768:N/ybgNcFXvtdgI2MyzNtRQtOflIwoHNV2XBFV72B4lA7Ps2Z+76g:AtdgI2MyzNtRQtOflIwoHNV2XBFV72B4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16DC2FBA2FAC424C4E4722277F873A2D91716FE9DB4139E1C20C87E155EF3645B499B0B
sha3_384: 1ff48fd7c71792a4f0b3fe0882221e6d5eb274fe625b7d7ec0ce4ce0c79aea4e8a1476c4a7756d07107fa000f5340904
ep_bytes: 5589e583ec3c6a008b15c8404000ffd2
timestamp: 2013-10-08 13:57:56

Version Info:

Comments:
CompanyName: IntelCorp
FileDescription: app.exe
FileVersion: 1.0.0.1
InternalName: app.exe
LegalCopyright: Copyright (C) 2002
LegalTrademarks:
OriginalFilename: app.exe
PrivateBuild:
ProductName: App
ProductVersion: 1.0.0.1
SpecialBuild:
Translation: 0x0800 0x0025

Trojan.Agent.BAVS also known as:

BkavW32.FamVT.GeND.Trojan
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.BAVS
FireEyeGeneric.mg.fee1d9ea4cb447de
CAT-QuickHealTrojanDownloader.Upatre.A6
ALYacTrojan.Agent.BAVS
CylanceUnsafe
VIPRETrojan.Agent.BAVS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f6811 )
K7GWTrojan-Downloader ( 0040f6811 )
Cybereasonmalicious.a4cb44
VirITTrojan.Win32.Zbot.CNJ
CyrenW32/Trojan3.GDX
SymantecTrojan.Zbot!gen71
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Trojan.Upatre-3362
KasperskyTrojan.Win32.Bublik.bhit
BitDefenderTrojan.Agent.BAVS
NANO-AntivirusTrojan.Win32.Bublik.cmtlal
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
AvastWin32:Kryptik-OEY [Trj]
TencentTrojan.Win32.Bublik.bhit
Ad-AwareTrojan.Agent.BAVS
SophosML/PE-A + Troj/Agent-AEDK
ComodoTrojWare.Win32.TrojanDownloader.Small.NAF@52ikdq
DrWebTrojan.DownLoader10.16610
ZillyaTrojan.Bublik.Win32.12161
TrendMicroTROJ_UPATRE.AGA
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.BAVS (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BAVS
JiangminTrojan/Bublik.gbo
AviraTR/Yarwi.A.11
Antiy-AVLTrojan/Generic.ASBOL.C6E4
ArcabitTrojan.Agent.BAVS
ZoneAlarmTrojan.Win32.Bublik.bhit
MicrosoftTrojan:Win32/Upatre.AMN!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Zbot.25088.I
McAfeePWSZBot-FIK
MAXmalware (ai score=81)
VBA32Trojan.Bublik
MalwarebytesTrojan.Agent.ED
TrendMicro-HouseCallTROJ_UPATRE.AGA
RisingMalware.FakePDF/ICON!1.9C28 (CLASSIC)
YandexTrojan.GenAsa!lAgja4fcQNY
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Upatre.Gen
FortinetW32/Krypt.SLO!tr
BitDefenderThetaGen:NN.ZexaF.34786.bq1@aGJCfKp
AVGWin32:Kryptik-OEY [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.BAVS?

Trojan.Agent.BAVS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment