Trojan

Trojan.Agent.BDMB removal instruction

Malware Removal

The Trojan.Agent.BDMB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BDMB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
files.000webhost.com

How to determine Trojan.Agent.BDMB?


File Info:

crc32: 10C1DF68
md5: 6a63e0c292dd9b2e4f4162b551235069
name: setup.exe
sha1: 7fadd86ed7eccc090c9ffa0c8f9c7f1d02107f9e
sha256: e9ce2449c21b966f7e597e5debdbf4220593aa8b669b1f82a0b8001526d3394a
sha512: aaf79e3311099dd15faa5cc011d2483fa05bcff772536ef3104e79e8eb4be3188ce01a8ac4471b1cf6fa77087b3038f22b5b18735aa874c3410a3674b42e19f4
ssdeep: 12288:AzDTo+c8NlvH0tGJjeM5u8v+VmlE2GLJ0u27iB3kd3HlFCG9L:gxbP0tkaM5Rwm62000BUd3HDCGJ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft 2019
Assembly Version: 1.1.0.0
InternalName: Microsoft.exe
FileVersion: 1.1.0.0
CompanyName: Microsoft
LegalTrademarks: Microsoft
Comments: Microsoft
ProductName: Microsoft
ProductVersion: 1.1.0.0
FileDescription: Application
OriginalFilename: Microsoft.exe

Trojan.Agent.BDMB also known as:

MicroWorld-eScanTrojan.Agent.BDMB
CAT-QuickHealTrojan.Dynamer
McAfeeGeneric BackDoor.adv
CylanceUnsafe
AegisLabTrojan.Win32.Generic.lBRs
K7GWTrojan ( 00503fce1 )
K7AntiVirusTrojan ( 00503fce1 )
Invinceaheuristic
BaiduMSIL.Trojan.Agent.bw
F-ProtW32/Msil.O
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Spy.Agent.XB
ClamAVWin.Trojan.Agent-1218694
Kasperskynot-a-virus:PSWTool.Win32.MessengerPass.n
BitDefenderTrojan.Agent.BDMB
AvastWin32:Malware-gen
Ad-AwareTrojan.Agent.BDMB
SophosMal/Behav-421
F-SecurePacked:MSIL/SmartIL.A
DrWebTrojan.PWS.Stealer.13008
McAfee-GW-EditionBehavesLike.Win32.Trojan.bc
FortinetMSIL/Agent.KBE!tr
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.BDMB (B)
IkarusHackTool.Win32.BrowserPassview
CyrenW32/Msil.AOXS-4373
JiangminTrojanSpy.MSIL.ewm
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Spy]/MSIL.Agent
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Tiggre!plock
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Agent.R114968
Acronissuspicious
VBA32TrojanSpy.MSIL.Agent
ALYacTrojan.Agent.BDMB
MalwarebytesTrojan.FakeMS.Gen
ArcabitTrojan.Agent.BDMB
YandexTrojan.Recube.Gen.LL
SentinelOnestatic engine – malicious
GDataTrojan.Agent.BDMB
AVGWin32:Malware-gen
Cybereasonmalicious.292dd9
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.22C9.Malware.Gen

How to remove Trojan.Agent.BDMB?

Trojan.Agent.BDMB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment