Trojan

Trojan.Agent.BPRR removal instruction

Malware Removal

The Trojan.Agent.BPRR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BPRR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Agent.BPRR?


File Info:

name: F9E958AC517F2B475E27.mlw
path: /opt/CAPEv2/storage/binaries/28a4a153b868c2b9f3eb7d396614cd2c48f978889b1ace4c56e3f25990b91ccd
crc32: 35F8A6C3
md5: f9e958ac517f2b475e27d3ee03d4f537
sha1: 0a7bc163bd019830fc12f87f0f74fff814203746
sha256: 28a4a153b868c2b9f3eb7d396614cd2c48f978889b1ace4c56e3f25990b91ccd
sha512: 661e8e366e38fb43616757512b7b7ac53a4e56efbe0b548e9f72f88c99f45156bb8021b9e5dba3465a24ffce718bb813efcb5b46ba2f9dfb8b6691829b39218e
ssdeep: 1536:Wh8Zc0c2TRH53F/y8fnFZTd6Ue6IWVvmfYC+zyl+U8/6OX:m8Zc0htH53F/y0nzTd6UjIWVvn+ov
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16924C06355B676CEF8B29F3E82E71D02CB4AB241476F845D25C2210F0904BD65E9FFA1
sha3_384: 2907dde2ee4ecb542029197220bc88fb6e53146e7d311a39536a3107a1fb6017e7bdb4b7c07de091286d64daed5212ef
ep_bytes: 558bec83ec24893424687c4940008914
timestamp: 2002-06-21 10:26:09

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Macromedia Flash Player 7.0 r19
FileVersion: 7,0,19,0
InternalName: Macromedia Flash Player 7.0
LegalCopyright: Copyright © 1996-2003 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: SAFlashPlayer.exe
ProductName: Shockwave Flash
ProductVersion: 7,0,19,0
Translation: 0x0409 0x04b0

Trojan.Agent.BPRR also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lkue
MicroWorld-eScanTrojan.Agent.BPRR
ClamAVWin.Packed.Ramnit-9946126-0
FireEyeGeneric.mg.f9e958ac517f2b47
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacTrojan.Agent.BPRR
CylanceUnsafe
VIPRETrojan.Agent.BPRR
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0047bf9a1 )
K7GWTrojan ( 0047bf9a1 )
Cybereasonmalicious.c517f2
BaiduWin32.Virus.Virut.gen
VirITTrojan.Win32.Cryptic.EBU
CyrenW32/Ramnit.H.gen!Eldorado
SymantecPacked.Protexor!gen1
Elasticmalicious (high confidence)
ESET-NOD32Win32/Ramnit.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BPRR
NANO-AntivirusTrojan.Win32.Rmnet.ddidny
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Zbot-OHP [Trj]
TencentTrojan.Win32.Ramnit.a
Ad-AwareTrojan.Agent.BPRR
EmsisoftTrojan.Agent.BPRR (B)
ComodoTrojWare.Win32.Spy.Zbot.WEBA@4min4f
DrWebTrojan.Rmnet.1
ZillyaTrojan.Lebag.Win32.229
TrendMicroTROJ_RAMNIT.SMD
McAfee-GW-EditionBehavesLike.Win32.Infected.dz
Trapminemalicious.high.ml.score
SophosML/PE-A + W32/Ramnit-BM
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BPRR
JiangminWin32/Virut.bv
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Nimnul
ArcabitTrojan.Agent.BPRR
ViRobotWorm.Win32.A.Net-Koobface.197632
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Krap.R27995
McAfeePWS-Zbot.gen.di
VBA32Malware-Cryptor.Win32.General.4
MalwarebytesMalware.AI.3305750983
TrendMicro-HouseCallTROJ_RAMNIT.SMD
RisingWorm.Win32.Koobface.ji (CLASSIC)
IkarusVirus.Win32.Heur
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KRYPTIK.FH!tr
BitDefenderThetaGen:NN.ZexaF.34606.nC0@aOMwdyfG
AVGWin32:Zbot-OHP [Trj]
PandaTrj/Pck_Pretorx.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.BPRR?

Trojan.Agent.BPRR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment