Trojan

Trojan.Agent.BBNR (B) information

Malware Removal

The Trojan.Agent.BBNR (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BBNR (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Agent.BBNR (B)?


File Info:

name: F03718505EB7EF9D78AC.mlw
path: /opt/CAPEv2/storage/binaries/1ffee9bf7030c3a640aae6ea9b13546f915f64cc23a4f38057f551293f865ce2
crc32: 2374F43C
md5: f03718505eb7ef9d78acfb0d606d23e5
sha1: 288f0ba6802b3b2dd2b6de22dbb5a38369349924
sha256: 1ffee9bf7030c3a640aae6ea9b13546f915f64cc23a4f38057f551293f865ce2
sha512: 897bbc453747deed38fc03be6da6d95e5e5a3ee40a9830f118bd433d8340db4e3550685e57c4a420c473c4f70c54bd86301534c34941b9dc45d5e4f6a38bdc27
ssdeep: 384:JGu2pAB5rUcqnPRrYYdYpTdhlL9OyeTtJRFwWEH/wW:JGuGSdMxdKhsttw9fwW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0D292F5AB8049A4C43786B8C876A48BB453B26E7D29694C49E37F073D3378355A384F
sha3_384: 147d2176c46fa0c4da50d0c046e37d3c414d0d547081cbe069d353da27833c38f26fad63398d2bebd361f215cfd040db
ep_bytes: b800104000e821010000e960feffffae
timestamp: 2013-10-27 16:00:06

Version Info:

0: [No Data]

Trojan.Agent.BBNR (B) also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BBNR
FireEyeGeneric.mg.f03718505eb7ef9d
McAfeeGenericRXHT-NB!F03718505EB7
CylanceUnsafe
VIPRETrojan.Win32.Upatre.jr (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Agent.BBNR
K7GWTrojan ( 0052964f1 )
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderThetaGen:NN.ZexaF.34182.bqX@ayUKHboi
CyrenW32/Zbot.ZW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
BaiduWin32.Trojan-Downloader.Waski.a
TrendMicro-HouseCallTROJ_UPATRE.SM13
AvastWin32:Agent-AUID [Trj]
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyTrojan-Spy.Win32.Zbot.znbz
NANO-AntivirusTrojan.Win32.Inject.cswlpr
TencentTrojan.Win32.Inject.hjqba
EmsisoftTrojan.Agent.BBNR (B)
ComodoTrojWare.Win32.Inject.HJR@59lmvg
DrWebTrojan.DownLoad.64857
ZillyaTrojan.Zbot.Win32.208522
TrendMicroTROJ_UPATRE.SM13
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/DwnLdr-LIQ
APEXMalicious
JiangminTrojan/Inject.arcs
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2AEB9AC
MicrosoftTrojan:Win32/Zbot.rmwh!MTB
GDataTrojan.Agent.BBNR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C3110476
VBA32Trojan.Inject
ALYacTrojan.Agent.BBNR
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3933661211
PandaTrj/Genetic.gen
RisingSpyware.Zbot!8.16B (RDMK:cmRtazqSfSK5hfP8EQoxk268NAuZ)
YandexTrojan.GenAsa!wLZCZt3dsQE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
Cybereasonmalicious.05eb7e

How to remove Trojan.Agent.BBNR (B)?

Trojan.Agent.BBNR (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment