Malware

Should I remove “Troj/Agent-BDKO”?

Malware Removal

The Troj/Agent-BDKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BDKO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Suspicious use of certutil was detected
  • Uses suspicious command line tools or Windows utilities

How to determine Troj/Agent-BDKO?


File Info:

name: EAD526A31B61680EB266.mlw
path: /opt/CAPEv2/storage/binaries/4b2590bd69a338fe34cc7563eaf3fedee459a18480ffd021848ba9ed9f3ce93d
crc32: F71FCA50
md5: ead526a31b61680eb26687713ebeee32
sha1: 57390f3413acb0ea3770764f04c125a489222174
sha256: 4b2590bd69a338fe34cc7563eaf3fedee459a18480ffd021848ba9ed9f3ce93d
sha512: 79573546187dd90ae49c1312947184fe2094d7f159f76a612d0485f673eacfc091b8dbe21f65a3526d80e985157aad3b326c12e9c82016dfc4adbcfd1da65a9b
ssdeep: 24576:AAHnh+eWsN3skA4RV1Hom2KXMmHa2nMviVT5+:3h+ZkldoPK8Ya2nwiv+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16E259D0273D1C036FFABA2739B6AF20556BD79254133852F13982DB9BD701B2263D663
sha3_384: f9dfbfdbd04283068dd79d341d8ab6b8aeb99e49e69828267874a4db86553c2ae1605214243de5c6d4d5c7e2747f4e50
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-06-01 11:11:54

Version Info:

Translation: 0x0809 0x04b0

Troj/Agent-BDKO also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46933677
FireEyeGeneric.mg.ead526a31b61680e
CAT-QuickHealTrojan.AutoIt.Injector.A5
ALYacTrojan.GenericKD.46933677
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
ArcabitTrojan.Generic.D2CC26AD
VirITTrojan.Win32.Dnldr28.CBIY
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecAUT.Heuristic!gen1
ESET-NOD32a variant of Win32/Packed.AutoIt.PC
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
ClamAVWin.Malware.Autoit-6989454-0
KasperskyTrojan.Script.Obit.gen
BitDefenderTrojan.GenericKD.46933677
TencentMalware.Win32.Gencirc.10b0d179
Ad-AwareTrojan.GenericKD.46933677
EmsisoftTrojan.GenericKD.46933677 (B)
DrWebTrojan.DownLoader28.36060
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosTroj/Agent-BDKO
AviraDR/AutoIt.Gen8
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan.Script.Obit.gen
GDataTrojan.GenericKD.46933677
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoinj02.Exp
McAfeeAutoIt/Injector.ax
VBA32Trojan.Autoit.Injcrypt
MalwarebytesBackdoor.Remcos
RisingTrojan.Injector/Autoit!1.BB8F (CLASSIC)
eGambitUnsafe.AI_Score_96%
FortinetAutoIt/Injector.EKY!tr
BitDefenderThetaAI:Packer.F34CB91817
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.31b616
PandaTrj/Genetic.gen
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Troj/Agent-BDKO?

Troj/Agent-BDKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment