Trojan

Win64/TrojanDownloader.Agent.BL malicious file

Malware Removal

The Win64/TrojanDownloader.Agent.BL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/TrojanDownloader.Agent.BL virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Win64/TrojanDownloader.Agent.BL?


File Info:

crc32: 4352A5B6
md5: b8cc4456fb2716b3ccb80e6a0ec6add4
name: 3.jpg
sha1: 6a78024a84168a90b56edc31454c72d7423ad928
sha256: 1ea02f1c9272cb00d9f589cb2f6e2b229cb2304baaeda8e3048948d3f4295b62
sha512: 47c86b04221240f0332b18d8ea89a651248cd944d43165325e677e4a9dabd476b2fe3e84ecd37d40366600d307795c6a39feca5f076c7dc4ff46ab9a926c0f19
ssdeep: 49152:7igc1CLzPq/foJcjpMMn/D27MQh3Hjf3Cc/imFtmz:7vc1uzPq/foJJuLv63Df3b/imFt+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win64/TrojanDownloader.Agent.BL also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Autoruns.GenericKDS.33608515
FireEyeGeneric.mg.b8cc4456fb2716b3
CAT-QuickHealTrojan.Win64
Qihoo-360Win64/Trojan.c67
McAfeeArtemis!B8CC4456FB27
MalwarebytesTrojan.Banker
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win64.Blackmoon.7!c
SangforMalware
K7AntiVirusTrojan ( 00561f401 )
BitDefenderTrojan.Autoruns.GenericKDS.33608515
K7GWTrojan ( 00561f401 )
Cybereasonmalicious.6fb271
TrendMicroTROJ_GEN.R049C0GB420
BitDefenderThetaGen:NN.ZedlaF.34104.fu4@aqOZI2ci
CyrenW64/Trojan.QCXG-7957
TrendMicro-HouseCallTROJ_GEN.R049C0GB420
Paloaltogeneric.ml
GDataTrojan.Autoruns.GenericKDS.33608515
KasperskyTrojan-Banker.Win64.Blackmoon.a
AlibabaBackdoor:Win32/Webdown.09d987cc
NANO-AntivirusTrojan.Win64.Banker1.gyfeqw
APEXMalicious
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
Ad-AwareTrojan.Autoruns.GenericKDS.33608515
SophosMal/Generic-S
ComodoMalware@#3b5pjdhbytm3b
F-SecureExploit.EXP/Equation.H
DrWebTrojan.PWS.Banker1.36317
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftTrojan.Autoruns.GenericKDS.33608515 (B)
SentinelOneDFI – Malicious
AviraTR/Dldr.Agent.npxco
MAXmalware (ai score=88)
Antiy-AVLTrojan[Banker]/Win64.Blackmoon
ArcabitTrojan.Autoruns.GenericS.D200D343
ZoneAlarmTrojan-Banker.Win64.Blackmoon.a
MicrosoftTrojanSpy:Win32/Golopy.A
VBA32Trojan.ShadowBrokers
ALYacTrojan.Autoruns.GenericKDS.33608515
CylanceUnsafe
ZonerTrojan.Win32.56355
ESET-NOD32a variant of Win64/TrojanDownloader.Agent.BL
TencentWin32.Trojan.Fakedoc.Auto
IkarusExploit.Equation.Eternalblue
FortinetW64/Blackmoon.A!tr
AVGWin64:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win64/TrojanDownloader.Agent.BL?

Win64/TrojanDownloader.Agent.BL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment