Malware

Application.Agent.BHR removal tips

Malware Removal

The Application.Agent.BHR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.BHR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.Agent.BHR?


File Info:

name: 23D371F7B73EB94F35A7.mlw
path: /opt/CAPEv2/storage/binaries/39e7ef37cd0abd219b4883f313e08e5ad88309b5edcc45841dfc04655f48881c
crc32: 35BD9C3A
md5: 23d371f7b73eb94f35a7b735488161d3
sha1: 2e93ed47c9f76146b91a5b3b3c6602626241e97c
sha256: 39e7ef37cd0abd219b4883f313e08e5ad88309b5edcc45841dfc04655f48881c
sha512: edd3721460608b425536e590fe4f7561eb6a64ebb4ee00d72b9a24396a8fd707a1edf5159f25725fb80811356663ed05dfb82841ef86db69d6e59a8e090b25bc
ssdeep: 12288:Bp1CGwl1m2CVurvJ4vyG8I0nQB7QAFZrEZvsX+E1PXonos7SBQIx:Lals2CVurygI0nQyAFZrPXa7Sz
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T13DF48C697BB400F9D5B7C139C9129627F6F2B816132097DF03A0876A2F236E55E3B721
sha3_384: ce8dc4f401da6a584f8f3d02f104a1faa7884fd587e9b961edb072c681da1a97036a06fb2ff52b31f870636883221509
ep_bytes: 4883ec28e89f0500004883c428e976fe
timestamp: 2017-11-30 10:14:32

Version Info:

0: [No Data]

Application.Agent.BHR also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Agent.BHR
FireEyeGeneric.mg.23d371f7b73eb94f
McAfeeArtemis!23D371F7B73E
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.96900
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win64/OpenSUpdater.11a2be58
CrowdStrikewin/malicious_confidence_60% (D)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Adware.OpenSUpdater.AA
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.DManager.gen
BitDefenderApplication.Agent.BHR
NANO-AntivirusRiskware.Win64.Searcher.fehstu
SUPERAntiSpywareTrojan.Agent/Gen-Injector
TencentMalware.Win32.Gencirc.10b14e8b
Ad-AwareApplication.Agent.BHR
EmsisoftApplication.Updater (A)
ComodoApplicUnwnt@#17d2cp5klvs2h
DrWebAdware.Searcher.3177
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA CO (PUA)
SentinelOneStatic AI – Malicious PE
GDataApplication.Agent.BHR
JiangminTrojan.Inject.acyw
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1108436
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.C2280744
Acronissuspicious
ALYacApplication.Agent.BHR
MAXmalware (ai score=97)
VBA32Adware.Searcher
MalwarebytesPUP.Optional.SpecialSearchOffer
YandexTrojan.Injector!8En0+HtcyI8
IkarusTrojan.Win32.Inject
eGambitUnsafe.AI_Score_50%
FortinetAdware/OpenSUpdater.235A

How to remove Application.Agent.BHR?

Application.Agent.BHR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment