Trojan

Trojan.Agent.BPAG removal instruction

Malware Removal

The Trojan.Agent.BPAG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BPAG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.BPAG?


File Info:

crc32: AD86C144
md5: 1b1af48fe1763db5e870208926beeb96
name: 1B1AF48FE1763DB5E870208926BEEB96.mlw
sha1: fb8dd94834055ca2f408655175eae0909bdd2469
sha256: 59ec60f232b17f3c80b05d3bd11f25978bbdd98bafdb323457993693e5cfd530
sha512: 56f6c9bdd76c6ce20bc5d1270b27a6ec17cc074aa8e374721a255116586774236b7a1118902c6adb31e58cf4ea2407823fb78d35927cc62cf0752dd3f8dbe3fd
ssdeep: 6144:yRAThFcbjmaW8KQuAAiEFPu04fhHsuq/FNRJITLsOIex1bUhz4w:8snQUIAiwu04ftsdXHITj3IN4w
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Unversed (C) 2012
InternalName: Ballades
FileDescription: Amethystine
OriginalFilename: Warships.exe
CompanyName: Counterpane Systems

Trojan.Agent.BPAG also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3158
CynetMalicious (score: 100)
CAT-QuickHealRansom.TesCrypt.S6
ALYacTrojan.Agent.BPAG
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.43936
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/TeslaCrypt.75abaf1c
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.fe1763
BaiduWin32.Trojan.Filecoder.k
CyrenW32/Trojan.CJXG-7645
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:TeslaCrypt-BC [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BPAG
NANO-AntivirusTrojan.Win32.Encoder.dzdboe
ViRobotTrojan.Win32.R.Agent.352256.D
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.Agent.BPAG
TencentMalware.Win32.Gencirc.10c57ae7
Ad-AwareTrojan.Agent.BPAG
SophosML/PE-A + Troj/Agent-APPM
ComodoMalware@#97lp8is6vlo5
BitDefenderThetaGen:NN.ZexaF.34628.vy0@a8knEJjG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.XXYZ
McAfee-GW-EditionRansom-Tescrypt.a
FireEyeGeneric.mg.1b1af48fe1763db5
EmsisoftTrojan.Agent.BPAG (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Yakes.dzr
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen8
eGambitGeneric.Malware
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Tescrypt!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Agent.BPAG
AhnLab-V3Trojan/Win32.Teslacrypt.C1312808
McAfeeRansom-Tescrypt.a
MAXmalware (ai score=100)
VBA32Trojan.Yakes
MalwarebytesMalware.Heuristic.1001
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.XXYZ
RisingTrojan.Ransom-Tesla!1.A322 (CLOUD)
YandexTrojan.Yakes!XdV2Ei5zvUA
IkarusTrojan-Ransom.TeslaCrypt
FortinetW32/TeslaCrypt.I!tr
AVGWin32:TeslaCrypt-BC [Trj]
Qihoo-360Win32/Ransom.Bitman.HgIASQkA

How to remove Trojan.Agent.BPAG?

Trojan.Agent.BPAG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment