Trojan

About “Trojan.Agent.BLVA” infection

Malware Removal

The Trojan.Agent.BLVA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BLVA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.BLVA?


File Info:

name: 8D00C21E8AF94581685D.mlw
path: /opt/CAPEv2/storage/binaries/ef2f386fbb9ee86b64f394d2ccecb33bbaa18a3a0159a4b94ed1388ab0bed557
crc32: D4B96351
md5: 8d00c21e8af94581685d70158d1cead5
sha1: d89f6fde680381c5630b74ebdeba44fb8be31e1b
sha256: ef2f386fbb9ee86b64f394d2ccecb33bbaa18a3a0159a4b94ed1388ab0bed557
sha512: e9a45d64ee7941391b1a098e25ecfcb438db4a6f18137e7ac4b6d9642733fcb02384ede556a2b6bfc1efb0326ba326ced90c8ac2a2ede9bff0181769ef001db4
ssdeep: 1536:Cu6h0hhDf4LHQMCNVU2aA0BZfbickhFW53oOME7yM5gJV0vhPnhQKX6:j7DfAkVU2i7DbkhFWrMzkv9M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199A38C05579D02A2F35B64308C257AB34AB47878765FABBFF3C6CE8E20A5EC0459065F
sha3_384: 44cc07aedd4deacf50e0cc7634a079b6d1871b997a042e9495def70ff913b7c3b8119bbc5cbc5db6a5469daba81198e6
ep_bytes: 558bec6a90688074400068e26c400064
timestamp: 2015-08-05 12:17:08

Version Info:

Comments:
CompanyName:
FileDescription: MoveWindow
FileVersion: 1, 0, 0, 1
InternalName먀MoveWindow: LegalCopyr
LegalCopyright: (C) 2012
LegalTrademarks:
OriginalFilename: MoveWindow.exe
PrivateBuild:
ProductName: MoveWindow
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: ࠐ₩

Trojan.Agent.BLVA also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BLVA
FireEyeGeneric.mg.8d00c21e8af94581
CAT-QuickHealTrojan.Ceeinject.17924
SkyhighPWSZbot-FAKV!8D00C21E8AF9
McAfeePWSZbot-FAKV!8D00C21E8AF9
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Agent.BLVA
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cd3381 )
AlibabaBackdoor:Win32/Bulta.e372a03c
K7GWTrojan ( 004cd3381 )
BitDefenderThetaGen:NN.ZexaF.36804.gy2@aaK1lyab
VirITTrojan.Win32.SHeur4.CLBA
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.CGUK
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Evo-gen [Trj]
ClamAVWin.Malware.Generickdz-7001603-0
KasperskyBackdoor.Win32.Hlux.dcm
BitDefenderTrojan.Agent.BLVA
NANO-AntivirusTrojan.Win32.BotFAKV.jpqrbz
TencentTrojan.Win32.Inject.vgce
SophosMal/Zbot-UE
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Siggen.59488
ZillyaTrojan.Hlux.Win32.541
TrendMicroTSPY_HPFAREIT.SMNA
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.BLVA (B)
IkarusTrojan.Win32.Kelihos
JiangminBackdoor/Hlux.gmk
WebrootTrojan.Dropper.Gen
VaristW32/S-4023b4d5!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Hack.Hlux.dcm
MicrosoftTrojan:Win32/Amadey.RPY!MTB
XcitiumTrojWare.Win32.Spy.Zbot.SBB@5te8th
ArcabitTrojan.Agent.BLVA
ZoneAlarmBackdoor.Win32.Hlux.dcm
GDataTrojan.Agent.BLVA
GoogleDetected
AhnLab-V3Trojan/Win32.MDA.R162280
Acronissuspicious
VBA32BScope.Trojan.Carbanak
ALYacTrojan.Agent.BLVA
TACHYONTrojan-PWS/W32.Tepfer.98554
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTSPY_HPFAREIT.SMNA
RisingTrojan.DllCheck!8.117DB (TFE:1:k8iicbVp6TV)
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.237AD3!tr
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Hlux.dcm

How to remove Trojan.Agent.BLVA?

Trojan.Agent.BLVA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment