Trojan

Trojan.Agent.BAYL malicious file

Malware Removal

The Trojan.Agent.BAYL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BAYL virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Trojan.Agent.BAYL?


File Info:

name: A3E2E59E3A21E632EB78.mlw
path: /opt/CAPEv2/storage/binaries/3effb96486e3ae8b1bd7420c38325766a894d5153c49e6812a03a52da52099d8
crc32: 96B381AD
md5: a3e2e59e3a21e632eb78b8edefa1845e
sha1: 9fb85fb97999e68642e20568dddba27f91f00abb
sha256: 3effb96486e3ae8b1bd7420c38325766a894d5153c49e6812a03a52da52099d8
sha512: e3bac5fcf43da46051d34cf84f599e539cc7e65b847d8cae8561adcbb9085546537f5ded9b797261215dbcb3bd8de8d2a5467535baf85eff9d06b606f10cb8ff
ssdeep: 6144:IwWTBJjyIF7Yhxnb/1bzHmU01VHVVihJAO6+29Li7GLYs8:IwWTr1sdJzHmU01VbO6/WRs8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F954AF56FEC641FADD9639704E6A6B3E9BFEE600131C45E3D3E45E881A411A0763C3CA
sha3_384: f828080a64dace4983d6048847cf26c507be61697e4f2c460b8ab8d0ed389eb283d6c752a541d4c93187e2442eb94136
ep_bytes: 558bec51535633f633c946e842f5ffff
timestamp: 2013-11-20 15:50:08

Version Info:

0: [No Data]

Trojan.Agent.BAYL also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
DrWebTrojan.PWS.Panda.5676
MicroWorld-eScanTrojan.Agent.BAYL
FireEyeGeneric.mg.a3e2e59e3a21e632
ALYacTrojan.Agent.BAYL
CylanceUnsafe
VIPRETrojan.Agent.BAYL
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004aea031 )
AlibabaTrojanSpy:Win32/ShellCode.eb7f37f9
K7GWTrojan ( 004aea031 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34806.sqW@ain1bjb
VirITTrojan.Win32.Generic.MZE
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecTrojan.Zbot!gm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAU
TrendMicro-HouseCallCryp_Xin1
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-64722
KasperskyTrojan-Spy.Win32.Zbot.qslz
BitDefenderTrojan.Agent.BAYL
NANO-AntivirusTrojan.Win32.Zbot.cqisgc
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastSf:Injector-G [Trj]
TencentTrojan.Win32.Zbot.aaw
Ad-AwareTrojan.Agent.BAYL
TrendMicroCryp_Xin1
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.BAYL (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BAYL
JiangminTrojanSpy.Zbot.dyiu
AviraTR/Spy.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.31
ArcabitTrojan.Agent.BAYL
MicrosoftPWS:Win32/Zbot!GO
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R90772
McAfeePWS-Zbot.gen.apr
VBA32BScope.Trojan.Zbot.6713
MalwarebytesMalware.AI.1106844228
APEXMalicious
RisingRansom.Satan!1.AEB7 (CLASSIC)
YandexTrojan.GenAsa!5hZa7nvAx10
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AAU!tr
AVGSf:Injector-G [Trj]
Cybereasonmalicious.e3a21e
PandaTrj/Genetic.gen

How to remove Trojan.Agent.BAYL?

Trojan.Agent.BAYL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment