Trojan

What is “Trojan.Agent.BMAW”?

Malware Removal

The Trojan.Agent.BMAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BMAW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Hongkong)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Writes a potential ransom message to disk
  • Attempts to delete or modify volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to ensure mapped drives are available from an elevated prompt or process with UAC enabled
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.BMAW?


File Info:

name: C9EF69554082BE3467DF.mlw
path: /opt/CAPEv2/storage/binaries/0db818ad2b03a8003c1b923985b3cd74ed82272205b3372796b192d2661824ac
crc32: F742762F
md5: c9ef69554082be3467df433a15e7ab45
sha1: 79c01bf85a712ddf6a4d54e9db281a8310a12c15
sha256: 0db818ad2b03a8003c1b923985b3cd74ed82272205b3372796b192d2661824ac
sha512: 13d818b734a9ee2d1cd2bda66ae6213f7fb7e9a74f0175ae37b85906816341e6224cdf1d5f57487e21b80d9782cee75db8acbd3752a303569fc8c6fa2598a4f9
ssdeep: 6144:cL42La41ctAaWLBbYcTDASiBdRIGt4MCZnsdbTo07BTT9OyIO:I42LasctABLBz/Udu04MEnsdbTo01VO8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12264AF3A34107039C8FBD9B1C9DB9549AB9DD671F3209D2F0884A74E5E0D765FB082EA
sha3_384: 49e400b67f926cf9c1df24b8dc4881da708ff4fdb23fa2198824719d14c66a4acacac2f56d98eff83fea0789ba87cea5
ep_bytes: 558bec6aff685066410068105d410064
timestamp: 2007-09-03 16:46:43

Version Info:

CompanyName: WinZip Computing, Inc.
FileDescription: Distributive
FileVersion: 173, 136, 217, 170
InternalName: Conjurers
LegalCopyright: Countries © 2059
OriginalFilename: Doomed.exe
ProductName: Crumblier Countesses

Trojan.Agent.BMAW also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1717
CynetMalicious (score: 100)
FireEyeGeneric.mg.c9ef69554082be34
CAT-QuickHealRansom.TeslaCrypt.WR4
ALYacTrojan.Agent.BMAW
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/Kryptik.f30e40ee
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.54082b
BitDefenderThetaGen:NN.ZexaF.34212.uq3@ayjmFabH
VirITTrojan.Win32.Crypt4.CBBJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DUJF
TrendMicro-HouseCallCryp_HpMyApp
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BMAW
NANO-AntivirusTrojan.Win32.Yakes.dvrmsw
MicroWorld-eScanTrojan.Agent.BMAW
AvastWin32:TeslaCrypt-EX [Trj]
TencentMalware.Win32.Gencirc.114c7aaa
Ad-AwareTrojan.Agent.BMAW
EmsisoftTrojan.Agent.BMAW (B)
ComodoMalware@#27mhxgru8xjqo
ZillyaTrojan.Yakes.Win32.38102
TrendMicroCryp_HpMyApp
McAfee-GW-EditionBehavesLike.Win32.Injector.fc
SophosMal/Generic-R + Mal/Tinba-L
IkarusTrojan.Win32.Crypt
GDataTrojan.Agent.BMAW
JiangminTrojan/Bitman.gm
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1219501
Antiy-AVLTrojan/Win32.Yakes
KingsoftWin32.Troj.GenericKD.v.(kcloud)
ArcabitTrojan.Agent.BMAW
ViRobotTrojan.Win32.Ransom.328798
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Skeeyah.A!rfn
SentinelOneStatic AI – Malicious PE
AhnLab-V3Win-Trojan/Lockycrypt.Gen
McAfeeTeslaCrypt!C9EF69554082
VBA32Trojan.Encoder
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
RisingTrojan.Ransom-Locky!8.4655 (CLOUD)
YandexTrojan.Bitman!F92GmfBFmfw
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Deshacop.XO!tr
AVGWin32:TeslaCrypt-EX [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.BMAW?

Trojan.Agent.BMAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment