Trojan

How to remove “Trojan.Agent.BFBM (B)”?

Malware Removal

The Trojan.Agent.BFBM (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BFBM (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Agent.BFBM (B)?


File Info:

name: 1F5006C1FC8D70628A36.mlw
path: /opt/CAPEv2/storage/binaries/cb4f49a97a344e496f00fc1fb1b2fcc046938280f101f98055cdc867f4d59cee
crc32: 017F51BF
md5: 1f5006c1fc8d70628a365d13b3e0b3af
sha1: 678a552d028f55eae0f1b5532de92a5e896214b5
sha256: cb4f49a97a344e496f00fc1fb1b2fcc046938280f101f98055cdc867f4d59cee
sha512: 4867ae39faf7433a68fc32089134553140ac1da822bb663f2cc6a5a6e008cd2e6a93e07551691a7c23a79fdbb7b1fdd215e6177571a88193916cf32d077b5345
ssdeep: 192:jTU9g9cVUz0wgJMGNT5NzNkFsZP1oynw0UWdto9KZjzqI/V2+m6DeVo9tlweddX:cVk0wrG7NRkSl16t8to9KJzqIE+m4wYt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15DA2B39A42D1793DD1660E7A15E2C7864634BC212F5982CF3E4DF508B83FAC3A8F075A
sha3_384: 5e30d1e2a5e5d9595e6c78af715e55862ea57dbf05cff192bfc5f439e477c461b9cbbdcf79b7b9bbaf653e6098e123cd
ep_bytes: 53b8ffff0010e8a2f9ffff5bc3ccff25
timestamp: 1995-08-29 04:02:04

Version Info:

FileDescription: JuJu
FileVersion: 2.1.2.11
LegalCopyright: Copyright 2009-2013 all authors
OriginalFilename: JuJu.exe
ProductName: JuJu
ProductVersion: 2.1.2.11
CompanyName: JuJu corporation
Translation: 0x0411 0x04b2

Trojan.Agent.BFBM (B) also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.Crypt.m2KH
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.30467
MicroWorld-eScanTrojan.Agent.BFBM
FireEyeGeneric.mg.1f5006c1fc8d7062
CAT-QuickHealTrojanDownloader.Upatre.AA4
McAfeeDownloader-FSH
CylanceUnsafe
VIPRETrojan.Win32.Upatre.buu (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaMalware:Win32/km_24892.None
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.1fc8d7
BitDefenderThetaAI:Packer.16E5CF4E1F
VirITTrojan.Win32.Generic.AW
CyrenW32/Trojan.RFPS-5185
SymantecBackdoor.Trojan
ESET-NOD32Win32/TrojanDownloader.Waski.A
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan-Downloader.Win32.Upatre.edv
BitDefenderTrojan.Agent.BFBM
NANO-AntivirusTrojan.Win32.Cryptodef.demivm
AvastWin32:Trojan-gen
TencentTrojan-Downloader.Win32.Waski.16000151
EmsisoftTrojan.Agent.BFBM (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaTrojan.Cryptodef.Win32.186
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionDownloader-FSH!1F5006C1FC8D
SophosML/PE-A + Troj/Upatre-EU
IkarusTrojan.Win32.Bublik
JiangminTrojan/Cryptodef.ax
AviraHEUR/AGEN.1120686
Antiy-AVLTrojan[Ransom]/Win32.Cryptodef
MicrosoftTrojanDownloader:Win32/Upatre
ZoneAlarmTrojan-Downloader.Win32.Upatre.edv
GDataTrojan.Agent.BFBM
AhnLab-V3Spyware/Win32.Zbot.C535016
VBA32Hoax.Cryptodef
MAXmalware (ai score=88)
MalwarebytesTrojan.Upatre
APEXMalicious
RisingDownloader.Waski!8.184 (CLOUD)
YandexTrojan.Cryptodef!QcEcO+hhoLs
SentinelOneStatic AI – Suspicious PE
FortinetW32/Waski.A!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.BFBM (B)?

Trojan.Agent.BFBM (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment