Malware

Troj/Agent-BCBY removal

Malware Removal

The Troj/Agent-BCBY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BCBY virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Troj/Agent-BCBY?


File Info:

name: 328F589587FDCBA085D6.mlw
path: /opt/CAPEv2/storage/binaries/0fb9ebe0ff573ebee37338f44b3f61be28125bb08e2a9ad0c0478f250d72f569
crc32: 25CB9A33
md5: 328f589587fdcba085d60872f87b4d5c
sha1: cc7147095dc86febc6003984b0c6e4751c5cc323
sha256: 0fb9ebe0ff573ebee37338f44b3f61be28125bb08e2a9ad0c0478f250d72f569
sha512: 9fd90cf9fae382d5685c3f5a7513eeb7bba20380daa4eacae823207708ab83962884f74b62aa56d6c735994147d18d77f9e464c5a5ba50c674251f93814e4859
ssdeep: 768:KOxZOgIryM1P3oO2y8UN2ivcTTJlu71TFA9nn0OjDDdmo/SK2OURvXZQIZ9:nSgy19JSVO1ONn511/tivXZQIT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10203F11D1DAE42F6CBAAC2F20D8C64C90416D16D466B33174EC6AEE48A487BD923950F
sha3_384: 0a447f97fcbdd11546bd699495bb78bc538711bb7e71ee17beef63587d3a2b996471faaf28c4180cbbc428f125b09ead
ep_bytes: bd2c4e4200c74500d4003f00b8d4eb3f
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Troj/Agent-BCBY also known as:

DrWebTrojan.Inject2.4876
MicroWorld-eScanGen:Packer.Krucky.B.ceX@ayxWNuo
FireEyeGeneric.mg.328f589587fdcba0
CAT-QuickHealTrojan.Dynamer.S5925524
SkyhighBehavesLike.Win32.Generic.nc
ALYacGen:Packer.Krucky.B.ceX@ayxWNuo
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Packer.Krucky.B.ceX@ayxWNuo
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaPacked:Win32/KKrunchy.cb7ffe3a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.95dc86
ArcabitGen:Packer.Krucky.B.EBCC41
BitDefenderThetaAI:Packer.529546AA1F
VirITTrojan.Win32.Inject2.HFO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.KKrunchy.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.kkrunchy-9937600-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Packer.Krucky.B.ceX@ayxWNuo
NANO-AntivirusTrojan.Win32.GenKryptik.fpevjn
AvastWin32:TrojanX-gen [Trj]
TencentBackdoor.Win32.Bifrose.we
EmsisoftGen:Packer.Krucky.B.ceX@ayxWNuo (B)
F-SecureTrojan.TR/Spy.Gen
ZillyaBackdoor.Bifrose.Win32.99154
Trapminemalicious.high.ml.score
SophosTroj/Agent-BCBY
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dfvtj
VaristW32/S-dd34b2aa!Eldorado
AviraTR/Spy.Gen
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.Kryptik.pe
Kingsoftmalware.kb.b.948
XcitiumTrojWare.Win32.Trojan.Inject.~INC@1f34i5
MicrosoftTrojanDropper:Win32/Dinwod
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Packer.Krucky.B.ceX@ayxWNuo
GoogleDetected
AhnLab-V3Trojan/Win32.Dinwod.R271738
McAfeeTrojan-FRBR!328F589587FD
VBA32Malware-Cryptor.General.3
Cylanceunsafe
RisingTrojan.Shyape!1.B5E8 (CLASSIC)
IkarusTrojan-Dropper.Win32.Dinwod
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BPCL!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Agent-BCBY?

Troj/Agent-BCBY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment