Trojan

What is “Trojan.Agent.BGNA”?

Malware Removal

The Trojan.Agent.BGNA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BGNA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Polish
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Created a service that was not started
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.BGNA?


File Info:

name: 7B7C92F2255A5BAEE981.mlw
path: /opt/CAPEv2/storage/binaries/911c634ae5c60d04ee20c59a996d79db490e069d4ab16aa2ef0e8defe1d3bad3
crc32: 1E8DE098
md5: 7b7c92f2255a5baee981af9737366dd1
sha1: 7efd6b6cf514362190df2d830c96f73597e83489
sha256: 911c634ae5c60d04ee20c59a996d79db490e069d4ab16aa2ef0e8defe1d3bad3
sha512: b70f0bd0b9d660a1ac54e538da7c9d68b65f879acaaaa355f5f91cb85aa370d339dae502544b3852532e65986b758025bd127440832b988712c86cedb82265af
ssdeep: 6144:UHFzKyizsjFNRfTV5HZ7dmuvvUf84t+ux9ScKLD62L:UHFmlzsjXL55ZmyvUf8bux9WD62L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FB49407A36E3CD4DB9A1639619061109F137DAFE14369DBBCCC66279003E67CFA09A9
sha3_384: 994837ccec9850eaf874cc8e287cd65daeb04dc5415a14e5f1e47e06676839818bfce3642498276e904559a2bc651ae2
ep_bytes: 558bec6aff68308247006810fa450064
timestamp: 2014-11-12 07:19:39

Version Info:

CompanyName: Barbosa
FileDescription: Barbozza Application
FileVersion: 1, 0, 0, 7
InternalName: Barbosa
LegalCopyright: Copyright (C) 2014
LegalTrademarks: Barbozzaa
OriginalFilename: barbosa.exe
ProductName: Barbozza Application
ProductVersion: 1, 0, 0, 7
Translation: 0x0416 0x04b0

Trojan.Agent.BGNA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BGNA
FireEyeGeneric.mg.7b7c92f2255a5bae
CAT-QuickHealTrojanRansom.Crowti.B4
McAfeeGeneric.vd
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Inject.Win32.120786
SangforInfostealer.Win32.Dyzap.mt
K7AntiVirusTrojan ( 004b00db1 )
AlibabaTrojanPSW:Win32/Battdil.e2407f7d
K7GWTrojan ( 004b00db1 )
CrowdStrikewin/malicious_confidence_90% (W)
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.SHeur4.CDTP
CyrenW32/Trojan.ICLL-8314
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Battdil.I
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Inject.sbef
BitDefenderTrojan.Agent.BGNA
NANO-AntivirusTrojan.Win32.Inject.efhcmi
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Inject.Bkjl
EmsisoftTrojan.Agent.BGNA (B)
F-SecureTrojan.TR/Battdil.524288
DrWebTrojan.DownLoader11.41469
VIPRETrojan.Agent.BGNA
TrendMicroTSPY_DYRE.AATZ
McAfee-GW-EditionGeneric.vd
GDataWin32.Trojan.Agent.AALT8R
JiangminTrojan.Inject.fye
WebrootW32.Malware.gen
AviraTR/Battdil.524288
Antiy-AVLTrojan/Win32.Inject
XcitiumMalware@#32b4r19uec85s
ArcabitTrojan.Agent.BGNA
ZoneAlarmTrojan.Win32.Inject.sbef
MicrosoftPWS:Win32/Dyzap
GoogleDetected
AhnLab-V3Trojan/Win32.Staser.R126122
BitDefenderThetaGen:NN.ZexaF.36350.Gq0@aKHIg@aO
ALYacTrojan.Agent.BGNA
MAXmalware (ai score=100)
VBA32Trojan.Inject
Cylanceunsafe
PandaTrj/WLT.B
ZonerTrojan.Win32.27439
TrendMicro-HouseCallTSPY_DYRE.AATZ
RisingStealer.Dyzap!8.13326 (TFE:5:HVFdsMz8nBE)
IkarusTrojan.Win32.Battdil
MaxSecureTrojan.Malware.7705764.susgen
FortinetW32/Kryptik.CPRJ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.2255a5
DeepInstinctMALICIOUS

How to remove Trojan.Agent.BGNA?

Trojan.Agent.BGNA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment