Trojan

Trojan.Agent.BCAY removal tips

Malware Removal

The Trojan.Agent.BCAY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BCAY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.BCAY?


File Info:

name: C14EEBAD6ACEEFB31D2D.mlw
path: /opt/CAPEv2/storage/binaries/0c2694c7d4a4a99a3dbd1e29b36a4617489132e201d36b3993c2c68017e5ecf6
crc32: CADFD32F
md5: c14eebad6aceefb31d2df2fbf4b518ae
sha1: 0168f23cff4fb94ed53b80524d1b8f2101116395
sha256: 0c2694c7d4a4a99a3dbd1e29b36a4617489132e201d36b3993c2c68017e5ecf6
sha512: dedda67a04ea7dbeec899c03bb78bf28bc528fdc4448acc40aef4e4da37c8a467ea21de0d195b1112665b46ae3faacfaa85d904afceac4794d091c2ee94b1841
ssdeep: 6144:7YQ2cMJ4y/bx/Kb4ZPMf2MSpdj/5wFhyy:MImbx/64ZPM+75Cy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1085412A08D69A4ABE743B5B29670F2100E6C399E877963B3C451EEEC174FD4346CA3C5
sha3_384: e15b5bfcf893488b61e08ba0e82e0920d655f14913daad6b332b17c7a6df6eb77e73ff47c68df7910a5f98d83cca7284
ep_bytes: 558bec51682c01000068d0ad4000ff15
timestamp: 1979-01-28 00:25:53

Version Info:

CompanyName: Cloud Company
FileDescription: Cloud Solution
FileVersion: 0.0.0.1
InternalName: Mission
LegalCopyright: Copyright (C) 2014
OriginalFilename: Mission
ProductName: Cloud
ProductVersion: 0.0.0.1
Translation: 0x0409 0x04b0

Trojan.Agent.BCAY also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillProc.31184
MicroWorld-eScanTrojan.Agent.BCAY
FireEyeGeneric.mg.c14eebad6aceefb3
CAT-QuickHealTrojan.ZbotCS.S1057157
ALYacTrojan.Agent.BCAY
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d6acee
BitDefenderThetaGen:NN.ZexaF.34182.ry0@aSIg86eO
VirITTrojan.Win32.Zbot.GCR
CyrenW32/Backdoor.TMJA-0002
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.ABP
TrendMicro-HouseCallTSPY_ZBOT.SMAAA
ClamAVWin.Trojan.Zeprox-1
KasperskyTrojan-Spy.Win32.Zbot.rtev
BitDefenderTrojan.Agent.BCAY
NANO-AntivirusTrojan.Win32.KillProc.cufwkc
SUPERAntiSpywareTrojan.Agent/Gen-PornoAsset
AvastWin32:Downloader-VAU [Trj]
TencentMalware.Win32.Gencirc.10c6c6b6
EmsisoftTrojan.Agent.BCAY (B)
ComodoTrojWare.Win32.Spy.Zbot.ABP@58f8p6
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.SMAAA
McAfee-GW-EditionBehavesLike.Win32.Flyagent.dc
SophosML/PE-A + Mal/ZAccess-CK
IkarusTrojan.Win32.Alureon
JiangminTrojanSpy.Zbot.eofv
AviraTR/PSW.Zbot.14260
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.8D795E
KingsoftHeur.SSC.2759346.0010.(kcloud)
MicrosoftPWS:Win32/Zbot
ZoneAlarmTrojan-Spy.Win32.Zbot.rtev
GDataWin32.Trojan.Agent.G8IDJM
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R102541
McAfeePWS-Zbot-FBDC!C14EEBAD6ACE
TACHYONTrojan-Spy/W32.ZBot.280576.AL
VBA32TrojanSpy.Zbot
MalwarebytesBackdoor.Agent.RND
APEXMalicious
RisingTrojan.Win32.Generic.168B7224 (C64:YzY0Or7mfqNedeYD)
YandexTrojanSpy.Zbot!VzDVdE/hDqY
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.CDCX!tr
AVGWin32:Downloader-VAU [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.BCAY?

Trojan.Agent.BCAY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment