Trojan

Trojan.Agent.BKMQ removal tips

Malware Removal

The Trojan.Agent.BKMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BKMQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Agent.BKMQ?


File Info:

name: 9ECC6367526528342BB3.mlw
path: /opt/CAPEv2/storage/binaries/1e5eef21084ebf742f04e7299e91bcbc9e62aabb86512e8b3160dca3b7715897
crc32: 099E715C
md5: 9ecc6367526528342bb39ff6b2b3d7b2
sha1: 01cdf02d0cff5a5d7fc5127907d4f1d4ef6b32a0
sha256: 1e5eef21084ebf742f04e7299e91bcbc9e62aabb86512e8b3160dca3b7715897
sha512: 3f7cc00c139d7710baf5b0f2be63dc349b1736bc230907dc6f63b5a34c58aed5a5d4fe4c6a9a3639b4848138a477df368a585c2e3e893ba7e28df1f4c158ce11
ssdeep: 1536:q+PJ+L6t5iM2YQHAL4W/vazsWFf5XVzs1aRW:dPQmtwLAp3azsshXlfRW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB73DF1BD59415B2CA7D89300EFA13BE9359A5A74EF98EE37348CE0E2C326941D3670D
sha3_384: 61e3a5202e62b18aaaa9a6849ba720444de285f509b8f8c945e0fe1b175baf9ec32204f3781a78eae1674d467f3880c1
ep_bytes: 558bec6aff68e03a400068c228400064
timestamp: 2015-06-11 17:18:27

Version Info:

0: [No Data]

Trojan.Agent.BKMQ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.mAZV
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader13.46597
MicroWorld-eScanTrojan.Agent.BKMQ
FireEyeGeneric.mg.9ecc636752652834
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-EV!9ECC63675265
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 004c7e1e1 )
AlibabaTrojanDownloader:Win32/Dorv.fcfa3485
K7GWTrojan ( 004c7e1e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34638.eqZ@aagfyGwb
VirITTrojan.Win32.Kazaki.J
CyrenW32/Zbot.YF.gen!Eldorado
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.CCSA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.AppWizard-9942507-1
KasperskyTrojan-Downloader.Win32.Agent.hfvv
BitDefenderTrojan.Agent.BKMQ
NANO-AntivirusTrojan.Win32.Agent.dsrrst
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.ifmoa
Ad-AwareTrojan.Agent.BKMQ
SophosML/PE-A + Mal/Zbot-UH
ComodoTrojWare.Win32.VirTool.CeeInject.KA@5sx8a4
ZillyaTrojan.Injector.Win32.266901
McAfee-GW-EditionPacked-EV!9ECC63675265
EmsisoftTrojan.Agent.BKMQ (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BKMQ
JiangminBackdoor/Hlux.gim
AviraTR/Kryptik.qgmqi
ZoneAlarmTrojan-Downloader.Win32.Agent.hfvv
MicrosoftVirTool:Win32/CeeInject
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dynamer.R153450
ALYacTrojan.Agent.BKMQ
MAXmalware (ai score=100)
VBA32Heur.Malware-Cryptor.Hlux
RisingTrojan.Win32.Generic.18C28BE5 (C64:YzY0Oqx6GSUZlVobvoOJ5X8K27w)
YandexTrojan.GenAsa!eVyoeMdjlkc
IkarusTrojan.Win32.Injector
FortinetW32/Generic.AC.19EDCC!tr
AVGWin32:Malware-gen
Cybereasonmalicious.752652
PandaTrj/Genetic.gen

How to remove Trojan.Agent.BKMQ?

Trojan.Agent.BKMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment