Malware

Troj/Agent-BGRP removal

Malware Removal

The Troj/Agent-BGRP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BGRP virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Agent-BGRP?


File Info:

name: 135A0B3165E99A1FAD05.mlw
path: /opt/CAPEv2/storage/binaries/dc96255e08d5fc36585d7c2c9495b4237173d4106995082b439a9ef0a2cc2186
crc32: 2D31528A
md5: 135a0b3165e99a1fad05b7a2aaa44af9
sha1: 173ef902d4b230455ba2f6e06a248a552598620d
sha256: dc96255e08d5fc36585d7c2c9495b4237173d4106995082b439a9ef0a2cc2186
sha512: 4d07d5f2b1b0952b7086ab96a40a4b71e411403914f0612e53359731aed9ec1c096db57cc0cde237716739c93caf3e78e62acffdeedca3fb2e2c2588d63ed02c
ssdeep: 12288:gFOCfp5fwQb45fwPPh2kkkkK4kXkkkkkkkkl888888888888888888nusMH0QiRs:gFOCfp5fB45foPh2kkkkK4kXkkkkkkkD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3E45C43EB93A63BC8AF963851379F17926ACC10FF9144CB2A98E9716DB15D830343D5
sha3_384: 67d47dcb9b75e790a228af5bda99b0b3554c6b65eefd0df8e75a81abe508d9a6d17efe84ec2d9a48c006b691e9c2beee
ep_bytes: 60909090909090b80010400090bbcc8e
timestamp: 1984-04-18 04:22:33

Version Info:

0: [No Data]

Troj/Agent-BGRP also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98113
FireEyeGeneric.mg.135a0b3165e99a1f
CAT-QuickHealBackdoor.Berbew.A6.MUE
ALYacTrojan.GenericKDZ.98113
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.028646BB21
VirITWorm.Win32.Berbew.G
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
ClamAVWin.Trojan.Crypted-28
BitDefenderTrojan.GenericKDZ.98113
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
TACHYONBackdoor/W32.Padodor
BaiduWin32.Trojan-Spy.Quart.a
VIPRETrojan.GenericKDZ.98113
Trapminemalicious.moderate.ml.score
SophosTroj/Agent-BGRP
IkarusTrojan.Crypt
JiangminTrojan.Generic.dzrgt
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.998
ArcabitTrojan.Generic.D17F41
GDataWin32.Trojan.PSE.11RRK8R
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.HangUp
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-Ransom.Win32.Pornoasset.a
SentinelOneStatic AI – Malicious PE
MaxSecureProxy.Qukart.gen
FortinetW32/Qukart.A!tr
Cybereasonmalicious.2d4b23
DeepInstinctMALICIOUS

How to remove Troj/Agent-BGRP?

Troj/Agent-BGRP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment