Trojan

Should I remove “Trojan.Agent.BLFD”?

Malware Removal

The Trojan.Agent.BLFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BLFD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Agent.BLFD?


File Info:

name: C657FF5DDFDCEBC6ECAD.mlw
path: /opt/CAPEv2/storage/binaries/eb999d347946a7d38c40c22d3cbd84c53a4a2f5e0707d4756e57fdf8a4324549
crc32: 4002C549
md5: c657ff5ddfdcebc6ecad15a4a0c94438
sha1: 3b0516c9eaaf2ec35bee460aa9d9f860460bfbde
sha256: eb999d347946a7d38c40c22d3cbd84c53a4a2f5e0707d4756e57fdf8a4324549
sha512: c6e65e9418d9bcf7bdbc126fb661b86485f748ae7c00a6af3f194a0fc8e3e83b14f5d0429a50a5560d66696e497224c2757e2b04029f34c0623828f5a6fe433f
ssdeep: 768:WC5NUHuE/tyZt+bVqiiqCwI4/jYdKjFej4SE5JF:lUHuExVqihlI4kdKEE5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135E26DEAAE200033C115D3385E5F973636F4D875AF53A38B76A2DE9D5932A58062320F
sha3_384: e6fa568bcadd3683d7ccb7f8d74934eeb30db1345955df8dbaff5fdb64d55cbe35d466d8aab539a17c315ce8d5eb9613
ep_bytes: 558bec6a9068d026400068a21d400064
timestamp: 2015-07-07 18:27:33

Version Info:

0: [No Data]

Trojan.Agent.BLFD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BLFD
CAT-QuickHealTrojan.Injector.100443
McAfeePWSZbot-FAKV!C657FF5DDFDC
CylanceUnsafe
VIPRETrojan.Win32.Injector.cdgy (v)
K7AntiVirusTrojan ( 004c7e1e1 )
BitDefenderTrojan.Agent.BLFD
K7GWTrojan ( 004c7e1e1 )
Cybereasonmalicious.ddfdce
BitDefenderThetaGen:NN.ZexaF.34182.cqY@ay46@fcb
VirITTrojan.Win32.Inject2.CNOA
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.CFDR
ClamAVWin.Malware.Blkx-6951312-0
KasperskyTrojan.Win32.Agent.ifuv
NANO-AntivirusTrojan.Win32.Yakes.dudaiy
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazpM+X3I3rTJSKcnPC+NDzpS)
SophosML/PE-A + Mal/Zbot-UE
ComodoTrojWare.Win32.VirTool.CeeInject.KGR@5t0fp3
DrWebTrojan.Encoder.1327
ZillyaTrojan.Injector.Win32.281089
McAfee-GW-EditionPWSZbot-FAKV!C657FF5DDFDC
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.c657ff5ddfdcebc6
EmsisoftTrojan.Agent.BLFD (B)
APEXMalicious
JiangminTrojan/Agent.ikeo
AviraTR/Kryptik.xbboqa
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASBOL.253A
MicrosoftVirTool:Win32/CeeInject.GK
ZoneAlarmTrojan.Win32.Agent.ifuv
GDataTrojan.Agent.BLFD
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CTBLocker.R158760
VBA32OScope.Malware-Cryptor.Hlux
ALYacTrojan.Agent.BLFD
MalwarebytesMalware.AI.798183777
PandaGeneric Suspicious
TencentMalware.Win32.Gencirc.10b4636f
YandexTrojan.Injector!206uONq2tzI
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.CFFW!tr
AVGSf:Agent-BA [Trj]
AvastSf:Agent-BA [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.BLFD?

Trojan.Agent.BLFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment