Malware

What is “Troj/Agent-BGRP”?

Malware Removal

The Troj/Agent-BGRP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BGRP virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Agent-BGRP?


File Info:

name: EB11BD8944A7C85D1AFD.mlw
path: /opt/CAPEv2/storage/binaries/3fd8ec828b110f9676e2aef88fe10b7858cdf5725d152148a2df63c2cfa6afa2
crc32: 96AE1193
md5: eb11bd8944a7c85d1afda86b86652466
sha1: cc699c7ce3a06f6d678dc89f4e53506335571cd7
sha256: 3fd8ec828b110f9676e2aef88fe10b7858cdf5725d152148a2df63c2cfa6afa2
sha512: ed1144ccc5770fcc5079cd6a5aff6d036e740e1253c329381e3f994143a8f2109dfc56dc0d75dfee3bf7418c74e8f838079d77bed2e6d44fa0c7813715d94ee3
ssdeep: 12288:7U/ZqCfp5fwQb45fwPPh2kkkkK4kXkkkkkkkkl888888888888888888nusMH0QN:4ECfp5fB45foPh2kkkkK4kXkkkkkkkka
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105E44C43EAD3A63BC8AB963841775F27936DCC20FF9640C71A98A971ADB05D831383D5
sha3_384: 143d9e1ac63f1dabc1e433e2ceb8c481b57f9ead960e279282da21a5fd1e0311ee145fec083bbac70bbf4efea85b9577
ep_bytes: 90906090909067e80000000090909090
timestamp: 1984-04-18 04:22:33

Version Info:

0: [No Data]

Troj/Agent-BGRP also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.S4Z@amSspHo
ClamAVWin.Trojan.Crypted-30
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.bh
McAfeeTrojan-FVOK!EB11BD8944A7
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusProxy-Program ( 003b8b111 )
K7GWProxy-Program ( 003b8b111 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.ShellObject.EE936C
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.vih
BitDefenderGen:Trojan.ShellObject.S4Z@amSspHo
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
EmsisoftGen:Trojan.ShellObject.S4Z@amSspHo (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.43874
VIPREGen:Trojan.ShellObject.S4Z@amSspHo
TrendMicroTROJ_GEN.R03BC0DAL24
FireEyeGeneric.mg.eb11bd8944a7c85d
SophosTroj/Agent-BGRP
IkarusTrojan-Spy.Win32.Qukart
JiangminTrojan.Generic.dzrgt
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.995
MicrosoftBackdoor:Win32/Berbew.AA!MTB
ZoneAlarmTrojan-Proxy.Win32.Qukart.vih
GDataWin32.Trojan.PSE.11RRK8R
VaristW32/Kryptik.JEE.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.028646BB21
ALYacGen:Trojan.ShellObject.S4Z@amSspHo
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.HangUp
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DAL24
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojan.PR.Qukart!eRgqdXuul6k
SentinelOneStatic AI – Malicious PE
MaxSecureProxy.Qukart.gen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.ce3a06
DeepInstinctMALICIOUS

How to remove Troj/Agent-BGRP?

Troj/Agent-BGRP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment