Trojan

Trojan.Agent.BFMV removal tips

Malware Removal

The Trojan.Agent.BFMV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BFMV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.BFMV?


File Info:

name: 92D629F71787762FC4CB.mlw
path: /opt/CAPEv2/storage/binaries/23348331d3d4e3772c3bd0ba4cbc77a5f1ae5c57b528aadc64635d98b45b1795
crc32: B1720E44
md5: 92d629f71787762fc4cb7bfb3d0a3a08
sha1: bfaa13be1910b462b5f96961286accf13c1112ce
sha256: 23348331d3d4e3772c3bd0ba4cbc77a5f1ae5c57b528aadc64635d98b45b1795
sha512: 8d28b867fa8a7a83e6905bcb2ffc3dfd7d480b5b0aff67f00eadb91fb02980f80e4bc3023d44d9e0e75a647762c603be60c71ce8393788659a386fe52408ec12
ssdeep: 768:kMly7VQJBIg9NSq4iNxX+AvivdFrDwh08SaYPDglcfe7A+O2IBlZ8obPvdti8/dY:kMo7VQDsiNx+FdFrDwzlvAejTq4fBPg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA93091ABBE44965E169273521FAC3E197B3B8585F53428F604862BD2C73F006E7E783
sha3_384: 8d212dc8720f95b079b7b428baee1d5ca1eaffc5321727c784fad83881f096218156ba69ac6fb9fa83804aa0aab4e685
ep_bytes: 68c4124000e8f0ffffff000000000000
timestamp: 2012-12-01 08:37:08

Version Info:

CompanyName: xwozlwr
ProductName: khmdatmq
FileVersion: 3.82
ProductVersion: 3.82
InternalName: ivfwjnp
OriginalFilename: ivfwjnp.exe

Trojan.Agent.BFMV also known as:

LionicWorm.Win32.WBNA.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BFMV
FireEyeGeneric.mg.92d629f71787762f
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.Downloader.nt
McAfeeW32/Autorun.worm.rd
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Agent.BFMV
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 005684c41 )
BitDefenderTrojan.Agent.BFMV
K7GWEmailWorm ( 005684c41 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Pronny.a
VirITTrojan.Win32.Generic.BWGT
SymantecTrojan.Gen.2
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VBObfus.IB
APEXMalicious
KasperskyWorm.Win32.WBNA.ipa
AlibabaWorm:Win32/VBObfus.edafe84e
NANO-AntivirusTrojan.Win32.Beebone.cmtitv
RisingWorm.WBNA!8.321 (TFE:3:D8Zf55s4SnS)
EmsisoftTrojan.Agent.BFMV (B)
F-SecureTrojan.TR/Beebone.22115468
DrWebTrojan.DownLoader7.33670
TrendMicroTSPY_SELFDEL_BL132AD9.TOMC
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-AC
IkarusTrojan.Win32.SelfDel
MAXmalware (ai score=100)
JiangminTrojan/Selfdel.hed
GoogleDetected
AviraTR/Beebone.22115468
VaristW32/VB.HM.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftTrojanDownloader:Win32/Beebone.FN
XcitiumTrojWare.Win32.VBO.ynf@4sido4
ArcabitTrojan.Agent.BFMV
ZoneAlarmWorm.Win32.WBNA.ipa
GDataTrojan.Agent.BFMV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.SelfDel.R45077
VBA32Trojan.SelfDel
ALYacTrojan.Agent.BFMV
TACHYONTrojan/W32.Agent.94208
DeepInstinctMALICIOUS
Cylanceunsafe
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallTSPY_SELFDEL_BL132AD9.TOMC
YandexTrojan.GenAsa!XsEzSLe/UAk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Selfdel.cly
FortinetW32/WBNA.IPA!worm
BitDefenderThetaGen:NN.ZevbaF.36792.fm0@auKu8Qii
AVGWin32:VB-AFEZ [Trj]
Cybereasonmalicious.e1910b
AvastWin32:VB-AFEZ [Trj]

How to remove Trojan.Agent.BFMV?

Trojan.Agent.BFMV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment