PUA

BV:Agent-BBK [PUP] removal

Malware Removal

The BV:Agent-BBK [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BV:Agent-BBK [PUP] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A script or command line contains a long continuous string indicative of obfuscation
  • Uses suspicious command line tools or Windows utilities

How to determine BV:Agent-BBK [PUP]?


File Info:

name: 5650DA5F2C90B6147303.mlw
path: /opt/CAPEv2/storage/binaries/848f0c8f9d2b7a2ccf1d41183c1ff4829ff9b813ec38241172b709f3a3bc664c
crc32: 609F9056
md5: 5650da5f2c90b61473039f827af3cb31
sha1: ab18615fbd62b0dd4f81f9069008d0bb3f0c4023
sha256: 848f0c8f9d2b7a2ccf1d41183c1ff4829ff9b813ec38241172b709f3a3bc664c
sha512: 9504e5a72f2b8a94a86c8a9958a47e75a3dd185399c918497186944dc4a8246ce5cdd478a1c3860ff3b943f5215baaf76004abd9de029b826cb4076273be5ae0
ssdeep: 24576:+fTkD0E003ubc2MRgCmP/ZwIDzq+Iha5a0Hc11c/p:KG00SSgCmP/ZwYj48a0811
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1F8357C6923EC43D8DA76E072FA12C707DEB3788A0674BB1B0DE04A766F13671161E752
sha3_384: 42553f735ad55a94dbe1f8f346b2017cbd8eca06bc96bfa6ed0338808cb8c756a032d888cc805d163a15339f56a798ad
ep_bytes: 4883ec28e8bfb300004883c428e936fe
timestamp: 2019-03-19 17:48:57

Version Info:

Translation: 0x0809 0x04b0

BV:Agent-BBK [PUP] also known as:

Elasticmalicious (high confidence)
DrWebTrojan.AutoIt.270
MicroWorld-eScanAIT:Trojan.Nymeria.383
ALYacAIT:Trojan.Nymeria.383
Cybereasonmalicious.f2c90b
SymantecPUA.Gen.2
ESET-NOD32multiple detections
TrendMicro-HouseCallCoinminer.AutoIt.MALXMR.SMGS
ClamAVWin.Trojan.Coinminer-6992285-0
Kasperskynot-a-virus:RiskTool.HTML.Miner.b
BitDefenderAIT:Trojan.Nymeria.383
NANO-AntivirusRiskware.Win64.Miner.jiosey
AvastBV:Agent-BBK [PUP]
TencentMalware.Win32.Gencirc.10b5522d
Ad-AwareAIT:Trojan.Nymeria.383
SophosGeneric ML PUA (PUA)
ComodoMalware@#2fbuvciwqeqvy
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.AutoIt.MALXMR.SMGS
McAfee-GW-EditionBehavesLike.Win64.TrojanAitInject.th
FireEyeGeneric.mg.5650da5f2c90b614
EmsisoftAIT:Trojan.Nymeria.383 (B)
IkarusTrojan.Win64.CoinMiner
GDataAIT:Trojan.Nymeria.383
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1100071
MicrosoftTrojan:Win32/Ditertag.A
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win64.CoinMiner.R268777
McAfeeTrojan-FPOR!5650DA5F2C90
MAXmalware (ai score=82)
MalwarebytesTrojan.BitCoinMiner.AutoIt
APEXMalicious
RisingHackTool.MinerCfg/JSON!1.BE59 (CLASSIC)
FortinetW64/CoinMiner.JK!tr
AVGBV:Agent-BBK [PUP]
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove BV:Agent-BBK [PUP]?

BV:Agent-BBK [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment