Malware

How to remove “Troj/Agent-BBMW”?

Malware Removal

The Troj/Agent-BBMW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BBMW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

How to determine Troj/Agent-BBMW?


File Info:

crc32: 4235A888
md5: a3d9f2c273d098b560acf43837907425
name: A3D9F2C273D098B560ACF43837907425.mlw
sha1: 1223e7e750bd92e896d599daa2113a6c34c824bc
sha256: 4439bfa2eb6eb55a44daef055197971de7cbe4b31712f908ca77105aa95930c3
sha512: fb02cb1c82232a35fb345355702f450312511d7d74675a5d46d9f3d56bd7b750b730a8e2265d8867a8c21205f7f146802a8df9ce3c95f54ad17adc60d3af344b
ssdeep: 1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIS7/ACB:ymb3NkkiQ3mdBjFIi/ACB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Agent-BBMW also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.317649
FireEyeGeneric.mg.a3d9f2c273d098b5
CAT-QuickHealTrojan.Wacatac.A2.mue
Qihoo-360HEUR/QVM19.1.293B.Malware.Gen
McAfeeGenericRXKA-HL!A3D9F2C273D0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Zusy.317649
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.273d09
CyrenW32/BlackMoon.P.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Blackmoon-9752571-1
KasperskyHEUR:Backdoor.Win32.Tiny.gen
TencentMalware.Win32.Gencirc.10b8f5e4
Ad-AwareGen:Variant.Zusy.317649
SophosTroj/Agent-BBMW
ComodoBackdoor.Win32.Agent.BVX@8hj67l
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Inject1.58305
ZillyaTrojan.Generic.Win32.643973
InvinceaML/PE-A + Troj/Agent-BBMW
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
EmsisoftGen:Variant.Zusy.317649 (B)
IkarusWorm.Win32.Ganelp
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.BlackMoon.a
MicrosoftWorm:Win32/Ganelp
GridinsoftTrojan.Win32.Vundo.ka!s1
ArcabitTrojan.Zusy.D4D8D1
ZoneAlarmHEUR:Backdoor.Win32.Tiny.gen
GDataWin32.Trojan.PSE.191P5TO
CynetMalicious (score: 100)
AhnLab-V3Malware/RL.Generic.R256000
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.diX@ai09iRm
ALYacGen:Variant.Zusy.317649
TACHYONTrojan/W32.Blamon
VBA32Backdoor.Tiny
MalwarebytesTrojan.Vundo
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
RisingTrojan.Agent!1.B82B (CLASSIC)
YandexTrojan.GenAsa!+V7EyyfQ22g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
FortinetW32/GenKryptik.CZVL!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Troj/Agent-BBMW?

Troj/Agent-BBMW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment