Malware

About “Troj/Agent-BGDH” infection

Malware Removal

The Troj/Agent-BGDH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BGDH virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Troj/Agent-BGDH?


File Info:

name: 1FE08D4110D48A32E69C.mlw
path: /opt/CAPEv2/storage/binaries/fc8e3ac0da7c673cfc70c7a1d6a11bd932d2841f4eaa6697177068a4187eaf5b
crc32: 9FAF246B
md5: 1fe08d4110d48a32e69cdd44c2f69e97
sha1: d2e145306ab81c49dd3653aca88a65ef57b68d4b
sha256: fc8e3ac0da7c673cfc70c7a1d6a11bd932d2841f4eaa6697177068a4187eaf5b
sha512: 81f440e7b6777a5bb76710f794ed26602f45ae20063544f880566fc82e07b27245793cba65ff3d195657def5f567737a5f5a36b60f3f2155a81d3cf12247b905
ssdeep: 1536:nSgy19JSVO1ONn511/tiOJXZzOmRkFOCWkdZnB5FDYlVzEuzHn84:nS7BE51XiOJpzOckFOi/B5FD2Eurn84
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF63F1604DD816F2CF6FCBF2CACD9C98041A51764A57281F56E4BBC41AACFA1E20B41F
sha3_384: daa02a4a8992ded99cc786929b92d47ac81af06eaa38a933d1098bb5f76467d1452f0c027f0b9a99f2a8cdb85c140a12
ep_bytes: bd2c4e4200c74500d4003f00b8d4eb3f
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Troj/Agent-BGDH also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.lqi8
MicroWorld-eScanGen:Packer.Krucky.B.eeZ@ayxWNuo
ClamAVWin.Malware.kkrunchy-9937600-1
FireEyeGeneric.mg.1fe08d4110d48a32
SkyhighBehavesLike.Win32.Generic.kc
McAfeeGenericRXMU-FR!1FE08D4110D4
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.1270188
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057168a1 )
AlibabaMalware:Win32/km_2a810.None
K7GWTrojan ( 0057168a1 )
Cybereasonmalicious.06ab81
BitDefenderThetaAI:Packer.94D6A46F1F
VirITTrojan.Win32.Inject2.HFO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.KKrunchy.AA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Packer.Krucky.B.eeZ@ayxWNuo
NANO-AntivirusTrojan.Win32.GenKryptik.fpevjn
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:TrojanX-gen [Trj]
TencentBackdoor.Win32.Bifrose.we
EmsisoftGen:Packer.Krucky.B.eeZ@ayxWNuo (B)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.Inject2.4876
VIPREGen:Packer.Krucky.B.eeZ@ayxWNuo
Trapminemalicious.high.ml.score
SophosTroj/Agent-BGDH
IkarusTrojan-Dropper.Win32.Dinwod
GDataWin32.Trojan.PSE.121QGH5
JiangminTrojan.Generic.dfvtj
GoogleDetected
AviraTR/Spy.Gen
Antiy-AVLGrayWare/Win32.Kryptik.pe
Kingsoftmalware.kb.b.999
XcitiumTrojWare.Win32.Trojan.Inject.~INC@1f34i5
ArcabitGen:Packer.Krucky.B.E49AC3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:Win32/Dinwod
VaristW32/S-dd34b2aa!Eldorado
AhnLab-V3Trojan/Win32.Dinwod.R271738
ALYacGen:Packer.Krucky.B.eeZ@ayxWNuo
MAXmalware (ai score=86)
VBA32Malware-Cryptor.General.3
Cylanceunsafe
PandaTrj/CI.A
RisingSpyware.Banker!1.BE71 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Krunchy.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Agent-BGDH?

Troj/Agent-BGDH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment