Trojan

Trojan.Agent.BCJZ information

Malware Removal

The Trojan.Agent.BCJZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BCJZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Agent.BCJZ?


File Info:

name: 2767C95B0F6311A96CF2.mlw
path: /opt/CAPEv2/storage/binaries/df530cc0a675721ab1244f7ad1f8aa5a16d556054d6e0b3b04af8f6aad55a20a
crc32: FD6428AF
md5: 2767c95b0f6311a96cf22651377fca94
sha1: e7094d8547285a6c2f7d2f53266afb7d63b31873
sha256: df530cc0a675721ab1244f7ad1f8aa5a16d556054d6e0b3b04af8f6aad55a20a
sha512: 7d46a9d6347abe97182fce3051865c01a893018e0073cc54d4c1dbb17db70dd6c9648e844975b16883f1e4a1ff79b3ba996cea31e757528debe64c1cc72beef8
ssdeep: 12288:zni29njkDHN9DIQp7t446DUA7uWz3pCuG6o87:znh4IQrBoUA7Pzcuno6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2C4F107F6B384F5FC28277260958771ED3938725AC00215DF54B1EA2EBB353DB16A2A
sha3_384: e329ee22655de8564d1477ee5ae22b489ae28a0aede4839abc8ccd18c807f79af611c8a105f38a6af6f28eac93c2ba86
ep_bytes: e834180000e9b7000000cccccc83ec08
timestamp: 2014-03-27 13:14:35

Version Info:

0: [No Data]

Trojan.Agent.BCJZ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.mae3
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BCJZ
FireEyeGeneric.mg.2767c95b0f6311a9
ALYacTrojan.Agent.BCJZ
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generic.8
K7AntiVirusTrojan ( 0040f8101 )
AlibabaTrojanPSW:Win32/Injector.a035972a
K7GWTrojan ( 0040f8101 )
Cybereasonmalicious.b0f631
BitDefenderThetaAI:Packer.74C2271521
VirITTrojan.Win32.Banker.AEM
CyrenW32/A-45cf753f!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BASH
BaiduWin32.Trojan.Inject.ai
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BCJZ
NANO-AntivirusTrojan.Win32.Buzus.cvylhh
SUPERAntiSpywareTrojan.Agent/Gen-Injector
APEXMalicious
TencentMalware.Win32.Gencirc.10c65602
Ad-AwareTrojan.Agent.BCJZ
SophosMal/Generic-R + Mal/Zbot-PI
ComodoTrojWare.Win32.Buzus.OLIJ@595jel
DrWebTrojan.PWS.Panda.5676
ZillyaTrojan.Buzus.Win32.120486
McAfee-GW-EditionBehavesLike.Win32.VirRansom.hc
EmsisoftTrojan.Agent.BCJZ (B)
IkarusBackdoor.Win32.Cidox
GDataTrojan.Agent.BCJZ
JiangminTrojan/Generic.azpgv
AviraTR/Inject.owlpanmz
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.944F36
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.C289204
Acronissuspicious
McAfeeDownloader-FEI!2767C95B0F63
TACHYONTrojan/W32.Buzus.544768.T
VBA32Trojan.Buzus
AvastWin32:Trojan-gen
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Buzus!vTEM50Jt7WY
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.RTMO!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Agent.BCJZ?

Trojan.Agent.BCJZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment