Malware

Troj/Agent-BGUD removal tips

Malware Removal

The Troj/Agent-BGUD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BGUD virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Creates a slightly modified copy of itself

Related domains:

www.ehWdZRoQ0Y.com
pastebin.com

How to determine Troj/Agent-BGUD?


File Info:

crc32: 7DD69FB9
md5: 14d1a903fa50c5737ecef17f518d87b3
name: 14D1A903FA50C5737ECEF17F518D87B3.mlw
sha1: f24e73598990ab1aef2e716818e38d0cd611387b
sha256: 08d1384d5d662b5966e27b157422c4a4e318ff94e4551de5b5fea374d6ab5d40
sha512: 10a96ce0e10e61a068fe3756cd434935458852117fe51fb9566b2194f92718b2a21c956d91c78cb69b782c726f7e1286e3eabfdb4c74fc1e14c23a1ffc2124e8
ssdeep: 24576:gmTl7uU1BJskriMnEVVO5VUAJzK/NcskriMnEVq:/l7fTJskriIIObUAzKWskriIH
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Troj/Agent-BGUD also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CAT-QuickHealTrojan.Generic
McAfeeGenericRXAA-FA!14D1A903FA50
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056e8c71 )
K7AntiVirusTrojan ( 0056e8c71 )
CyrenW32/Kryptik.CWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GWT
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.75694
MicroWorld-eScanTrojan.GenericKDZ.75694
Ad-AwareTrojan.GenericKDZ.75694
SophosTroj/Agent-BGUD
BitDefenderThetaGen:NN.ZexaF.34170.8iZ@ayGm3To
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
FireEyeGeneric.mg.14d1a903fa50c573
EmsisoftTrojan.GenericKDZ.75694 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hazic
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.329B1DA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D127AE
GDataTrojan.GenericKDZ.75694
AhnLab-V3Malware/Win32.Generic.R373212
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=84)
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Agent!3+Q9wXHmm7A
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.FFP!tr
AVGWin32:Trojan-gen

How to remove Troj/Agent-BGUD?

Troj/Agent-BGUD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment