Trojan

Trojan.Agent.BBNR malicious file

Malware Removal

The Trojan.Agent.BBNR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BBNR virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Agent.BBNR?


File Info:

name: 796A6F2406F0FE5F9F95.mlw
path: /opt/CAPEv2/storage/binaries/cbbd9160cc7fdd6f1f8068e9cd2fe5c564208c3fb1ab178b344b464d0db3567e
crc32: C9848832
md5: 796a6f2406f0fe5f9f95fcc8ef3ff7c4
sha1: 1fa4c80edc5e34a39187d4e697588f0bb34be5f9
sha256: cbbd9160cc7fdd6f1f8068e9cd2fe5c564208c3fb1ab178b344b464d0db3567e
sha512: 6c653e63ee506af28296a6262b11f1bb6064d7994df626acd5e159a432041588a554e2abb3d0cd5a77bdb50477beb90875233fd8ce55f31a8937a5d29c2ae9ad
ssdeep: 384:JGu2pAB5rUcqnPRrYYdYpTdhlL9OyeTtJRFwWEH/w/:JGuGSdMxdKhsttw9fw/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7D292F5AB8049A4C43786B8C876A48BB453B26E7D29694C49D37F073D3378355A384F
sha3_384: b92ddda1981ac2b1e975a04f11e7ae730d91347b564b94f75ea0206da34131ea17361297fb9be57e65793b138a4156d5
ep_bytes: b800104000e821010000e960feffffae
timestamp: 2013-10-27 16:00:06

Version Info:

0: [No Data]

Trojan.Agent.BBNR also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BBNR
FireEyeGeneric.mg.796a6f2406f0fe5f
ALYacTrojan.Agent.BBNR
CylanceUnsafe
VIPRETrojan.Win32.Upatre.jr (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.Agent.BBNR
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Zbot.ZW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyTrojan-Spy.Win32.Zbot.znbz
NANO-AntivirusTrojan.Win32.Inject.cswlpr
RisingSpyware.Zbot!8.16B (RDMK:cmRtazqSfSK5hfP8EQoxk268NAuZ)
Ad-AwareTrojan.Agent.BBNR
EmsisoftTrojan.Agent.BBNR (B)
ComodoTrojWare.Win32.Inject.HJR@59lmvg
DrWebTrojan.DownLoad.64857
ZillyaTrojan.Zbot.Win32.208522
TrendMicroTROJ_UPATRE.SM13
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
SophosML/PE-A + Troj/DwnLdr-LIQ
IkarusTrojan-Downloader.Win32.Upatre
JiangminTrojan/Inject.arcs
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.2AEB9AC
MicrosoftTrojan:Win32/Zbot.rmwh!MTB
GDataTrojan.Agent.BBNR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C3110476
Acronissuspicious
McAfeeGenericRXHT-NB!796A6F2406F0
VBA32Trojan.Inject
MalwarebytesMalware.AI.3933661211
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM13
TencentTrojan.Win32.Inject.hjqba
YandexTrojan.GenAsa!wLZCZt3dsQE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34182.bqX@ayUKHboi
AVGWin32:Agent-AUID [Trj]
Cybereasonmalicious.406f0f
AvastWin32:Agent-AUID [Trj]

How to remove Trojan.Agent.BBNR?

Trojan.Agent.BBNR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment