Malware

Troj/Agent-BBIM (file analysis)

Malware Removal

The Troj/Agent-BBIM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BBIM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Troj/Agent-BBIM?


File Info:

name: 254F68A889C456666D7B.mlw
path: /opt/CAPEv2/storage/binaries/bf7ee0d7f5efb2298b8424c56a01e45c3321d91cef6f3320bf26cf63dde1325e
crc32: 19509C43
md5: 254f68a889c456666d7b2721f64cf1a5
sha1: 4f10466726565145dea2866450611e06c23c0a8e
sha256: bf7ee0d7f5efb2298b8424c56a01e45c3321d91cef6f3320bf26cf63dde1325e
sha512: a310c853160544fcef5d8e56ff561e3886f332f256098fb18a5eb5319c94ac7543dda5e188be1af89b9a40f7a843d3e644793fb97e07a63028a99a13742f6573
ssdeep: 3072:ymb3NkkiQ3mdBjFo73PYP1lri3KoSV31x4xLe:n3C9BRo7MlrWKo+lxKe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E2419F60FADE5F6E6B0B83146B59468045AB2B71E821DE850F913850F7D8C25AC2C7F
sha3_384: 3622e21ebc99221717bf49501bbe9f1845b9c3afaaeb9b396a7a7bcb726b1b11d8561de2f3ef94caf1ba2c9eee4a7728
ep_bytes: b800804200608da80080fdff68e93df1
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Troj/Agent-BBIM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.BlackMoon.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35816276
FireEyeGeneric.mg.254f68a889c45666
CAT-QuickHealTrojan.GenericCS.S5480318
SkyhighBehavesLike.Win32.Dropper.dm
ALYacTrojan.GenericKD.35816276
Cylanceunsafe
ZillyaTrojan.Generic.Win32.664594
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00568e321 )
AlibabaWorm:Win32/Agent.535778b3
K7GWTrojan ( 00568e321 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D2228354
BitDefenderThetaGen:NN.ZexaF.36608.niZ@ai09iRm
VirITTrojan.Win32.Inject1.DIGN
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Midie-9378795-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.35816276
SUPERAntiSpywareTrojan.Agent/Gen-Vundo
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Agent!1.B82B (CLASSIC)
TACHYONTrojan/W32.Blamon
EmsisoftTrojan.GenericKD.35816276 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Inject1.58305
VIPRETrojan.GenericKD.35816276
TrendMicroTROJ_GEN.R03BC0DLP23
Trapminemalicious.high.ml.score
SophosTroj/Agent-BBIM
IkarusWorm.Win32.Ganelp
WebrootW32.Trojan.Gen
VaristW32/Ganelp.A.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare/Win32.Blackmoon.a
Kingsoftmalware.kb.b.1000
GridinsoftTrojan.Win32.Vundo.ka!s1
XcitiumBackdoor.Win32.Agent.BVX@8hj67l
MicrosoftWorm:Win32/Ganelp
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1O0BVLU
GoogleDetected
AhnLab-V3Malware/RL.Generic.R256000
Acronissuspicious
McAfeeGenericRXAA-AA!254F68A889C4
MAXmalware (ai score=88)
VBA32Backdoor.Tiny
MalwarebytesVirlock.Ransom.FileInfector.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLP23
TencentPacked.Win32.BlackMoon.ha
YandexTrojan.GenAsa!+V7EyyfQ22g
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Inject.EHCO!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.726565
DeepInstinctMALICIOUS

How to remove Troj/Agent-BBIM?

Troj/Agent-BBIM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment