Malware

Troj/Agent-BGDH (file analysis)

Malware Removal

The Troj/Agent-BGDH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BGDH virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Troj/Agent-BGDH?


File Info:

name: 81F2F9E624906829A092.mlw
path: /opt/CAPEv2/storage/binaries/b3cae6fe7379bea86a9c54e4ceb3bd0401a3f34dfe9c18c0c24d94fc351a87e6
crc32: 3877E0D4
md5: 81f2f9e624906829a0928e34c1ff4d75
sha1: ff0e442b352252d444a1de6d530abb46c040cb1f
sha256: b3cae6fe7379bea86a9c54e4ceb3bd0401a3f34dfe9c18c0c24d94fc351a87e6
sha512: bc9716609f9012f12efd9b118ed594812c45c342a8dd1c4be013fffb4a8e4a6a21342eb92134351822c070be67a90c3c87d41d024465a09390d6e36b1b6eba5b
ssdeep: 1536:nSgy19JSVO1ONn511/tiOJXZzOmRkFOCWkdZnB5FDYlVzEuzHn0:nS7BE51XiOJpzOckFOi/B5FD2Eurn0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B63F1605CC816F2CF7FC7F289C99C98041A51774B52281F56E4BBC41AACFA1E24B45F
sha3_384: d9153deb34a00d119213ac8bda2883b94a7b25bbff8c0dc29994483543887f6dcf5ab0964e13c1d8c9666bd172de4c63
ep_bytes: bd2c4e4200c74500d4003f00b8d4eb3f
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Troj/Agent-BGDH also known as:

DrWebTrojan.Inject2.4876
MicroWorld-eScanGen:Packer.Krucky.B.eeZ@ayxWNuo
SkyhighBehavesLike.Win32.Generic.kc
McAfeeGenericRXMU-FR!81F2F9E62490
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.1270188
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057168a1 )
BitDefenderGen:Packer.Krucky.B.eeZ@ayxWNuo
K7GWTrojan ( 0057168a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.94D6A46F1F
VirITTrojan.Win32.Inject2.HFO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.KKrunchy.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.kkrunchy-9937600-1
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.GenKryptik.fpevjn
RisingSpyware.Banker!1.BE71 (CLASSIC)
SophosTroj/Agent-BGDH
F-SecureTrojan.TR/Spy.Gen
VIPREGen:Packer.Krucky.B.eeZ@ayxWNuo
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.81f2f9e624906829
EmsisoftGen:Packer.Krucky.B.eeZ@ayxWNuo (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dfvtj
VaristW32/S-dd34b2aa!Eldorado
AviraTR/Spy.Gen
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.Kryptik.pe
Kingsoftmalware.kb.b.999
MicrosoftTrojanDropper:Win32/Dinwod
XcitiumTrojWare.Win32.Trojan.Inject.~INC@1f34i5
ArcabitGen:Packer.Krucky.B.E49AC3
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Packer.Krucky.B.eeZ@ayxWNuo
GoogleDetected
AhnLab-V3Trojan/Win32.Dinwod.R271738
ALYacGen:Packer.Krucky.B.eeZ@ayxWNuo
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.General.3
Cylanceunsafe
TencentBackdoor.Win32.Bifrose.we
IkarusTrojan-Dropper.Win32.Dinwod
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Krunchy.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b35225
AvastWin32:TrojanX-gen [Trj]

How to remove Troj/Agent-BGDH?

Troj/Agent-BGDH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment