Trojan

What is “Trojan.Agent.BPDV”?

Malware Removal

The Trojan.Agent.BPDV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BPDV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
myexternalip.com
ocsp.pki.goog
hotbizlist.com
sofiehughesphotography.com
www.hugedomains.com
crl.pki.goog
crls.pki.goog
ocsp.digicert.com
goedkoop-weekendjeweg.net
coatesarchitecture.com
adamhughes.in
magaz.mdoy.pro
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org

How to determine Trojan.Agent.BPDV?


File Info:

crc32: 5C09DB04
md5: e9caa5613389ef36e6f61397e8c529d1
name: E9CAA5613389EF36E6F61397E8C529D1.mlw
sha1: ddf3f7ab31a2d508c3ea49655c5cd66c47fc3b56
sha256: 128be1f65bfbf3ee157eb313a9c5a3bec5a0255100d3add7ee0f8563df56cf51
sha512: dd9c109c0a16dd43f8432ef2b16decf2f604984aa13fcf8f3861c11d0187b6f335836b641b6ab9c1855a8564b9f34784901efeb9143cb686765f9a1e38038e1b
ssdeep: 6144:/i8zAOSx+mgvGOaLw86ma676uBa9IwBja40qJE1u9DS8odfyS:/FAUmge90qsiwBax1udMz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.BPDV also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004d97831 )
LionicTrojan.Win32.Bitman.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.10956
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.B4
ALYacTrojan.Agent.BPDV
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.1533
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tescrypt.827fb681
K7GWTrojan ( 004d97831 )
Cybereasonmalicious.13389e
BaiduWin32.Trojan.Kryptik.th
CyrenW32/Agent.XL.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
ZonerTrojan.Win32.37170
APEXMalicious
AvastWin32:TeslaCrypt-B [Trj]
ClamAVWin.Ransomware.TeslaCrypt-9873543-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BPDV
NANO-AntivirusTrojan.Win32.Inject.dzgjuw
ViRobotTrojan.Win32.Kryptik.Gen.A
MicroWorld-eScanTrojan.Agent.BPDV
TencentMalware.Win32.Gencirc.10c5b4c0
Ad-AwareTrojan.Agent.BPDV
SophosML/PE-A + Troj/Ransom-BVS
ComodoMalware@#1qkrdvas2dtlj
BitDefenderThetaGen:NN.ZexaF.34790.vqW@aaFSQjnG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HPEPING.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.e9caa5613389ef36
EmsisoftTrojan.Agent.BPDV (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Bitman.bh
WebrootW32.Trojan.Gen
AviraTR/AD.RunExp.Y.855
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1614A1E
MicrosoftRansom:Win32/Tescrypt.C
ArcabitTrojan.Agent.BPDV
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.BPDV
TACHYONTrojan/W32.Bitman.358912
AhnLab-V3Trojan/Win32.Teslacrypt.C1313883
Acronissuspicious
McAfeeRansomware-FBT!E9CAA5613389
MAXmalware (ai score=100)
VBA32BScope.Trojan.Inject
MalwarebytesRansom.TeslaCrypt
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_HPEPING.SM
RisingTrojan.Kryptik!1.A31F (CLASSIC)
YandexTrojan.Bitman!sh7Bu20FfAk
IkarusTrojan.Crypt
FortinetW32/FORUCON.BME!tr
AVGWin32:TeslaCrypt-B [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Tescrypt.HwoCEpsA

How to remove Trojan.Agent.BPDV?

Trojan.Agent.BPDV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment