Malware

Troj/Agent-BGPW information

Malware Removal

The Troj/Agent-BGPW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BGPW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Agent-BGPW?


File Info:

crc32: D5A863DB
md5: 0ea120f89f06c0083563d41e08d09040
name: 0EA120F89F06C0083563D41E08D09040.mlw
sha1: b665f1b6bd4f8d83f4d7119c268d3411a69abe52
sha256: c1fe038816032cdb4456d41a6cabeeddf3d6b70166326d331fea727567ef1797
sha512: 81b100cac46d1566df789fb2affaa3425ba2a0d2b463a7c12ec8f1395fb939e7473dd682da63cd0d7e4745e14dc3ea58dfc189ca32059e1af051d220983ad5d1
ssdeep: 12288:gq01B+5M7UYTfmQOohSdgSH1KTAOPBo3+zHYTfm:q/cM4mfBhShH1EAemf
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Troj/Agent-BGPW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057ffc71 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.364231
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Copak.dd4badff
K7GWTrojan ( 00539ec91 )
Cybereasonmalicious.89f06c
CyrenW32/Razy.GL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Jaiko-9832778-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Zusy.364231
NANO-AntivirusTrojan.Win32.Copak.iyvzuu
MicroWorld-eScanGen:Variant.Zusy.364231
TencentMalware.Win32.Gencirc.10ce33aa
Ad-AwareGen:Variant.Zusy.364231
SophosTroj/Agent-BGPW
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34236.@mZ@aak9Dng
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03FC0RF121
McAfee-GW-EditionBehavesLike.Win32.Sytro.fh
FireEyeGeneric.mg.0ea120f89f06c008
EmsisoftGen:Variant.Zusy.364231 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.afbe
AviraHEUR/AGEN.1131762
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.34301C2
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Zusy.364231
AhnLab-V3Malware/Win32.Generic.C2706613
McAfeeGenericRXAA-AA!0EA120F89F06
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03FC0RF121
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Copak!aV2q9UK12I4
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Troj/Agent-BGPW?

Troj/Agent-BGPW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment