Trojan

Trojan.Agent.BRKA removal guide

Malware Removal

The Trojan.Agent.BRKA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BRKA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Bulgarian
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.BRKA?


File Info:

crc32: D6F4ADB5
md5: 5d81e04abea581cd314aceabafaaff18
name: 5D81E04ABEA581CD314ACEABAFAAFF18.mlw
sha1: e71254283e5fe4701eea95c0bab62cc794f38cdc
sha256: d37f1e805b3f9873ce76f18ea930c6fa0a7b8a9d6bc319404471e70e396f791a
sha512: 6c50e72f37ccbb5f7ce7130b2607fa668bff238ced5f3d646c4f6c6dfdcd873706e96d5e3bf8a16cc32b52322ec71c06056df44dc65b33ec60602faa048343a0
ssdeep: 6144:K9iqsrJ0LOMc6iAOhgrwOaSq1YXyDTQHZgpNMUpmC+OkykD+Wyasv:Kgqslsc5fUcGnHSpN7ICCyi1I
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 '1C' 1996-2013
InternalName: Enterprise
FileVersion: 8.3.3.665
CompanyName: 1C
Comments: 1C:Enterprise 8 app
ProductName: 1C:Enterprise 8.3
ProductVersion: 8.3.3.665
FileDescription: Enterprise
OriginalFilename: Enterprise.exe
Translation: 0x0419 0x04b0

Trojan.Agent.BRKA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056ec671 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4084
CynetMalicious (score: 100)
CAT-QuickHealRansomware.Teslacrypt.P7
ALYacTrojan.Agent.BRKA
CylanceUnsafe
ZillyaTrojan.Bitman.Win32.1421
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.3e9b07a1
K7GWTrojan ( 0056ec671 )
Cybereasonmalicious.abea58
BaiduWin32.Trojan.Kryptik.aio
CyrenW32/Rovnix.C.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.EQIQ
ZonerTrojan.Win32.40415
APEXMalicious
AvastWin32:Mutex-A [Trj]
ClamAVWin.Ransomware.TeslaCrypt-7549401-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BRKA
NANO-AntivirusTrojan.Win32.Bitman.eawowi
ViRobotTrojan.Win32.R.Agent.416256.H
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.Agent.BRKA
TencentMalware.Win32.Gencirc.10c1820a
Ad-AwareTrojan.Agent.BRKA
SophosML/PE-A + Mal/Wonton-BZ
ComodoTrojWare.Win32.Yakes.QIQ@6b1i0d
BitDefenderThetaGen:NN.ZexaF.34628.zu0@aSWiVUpS
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPTESLA.SM1
McAfee-GW-EditionBehavesLike.Win32.Ramnit.gh
FireEyeGeneric.mg.5d81e04abea581cd
EmsisoftTrojan.Agent.BRKA (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm.Ngrbot.ol
WebrootRansom.Telsacrypt.Gen
AviraHEUR/AGEN.1114506
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tescrypt!rfn
ArcabitTrojan.Agent.BRKA
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Agent.BRKA
TACHYONTrojan/W32.Bitman.416256
AhnLab-V3Trojan/Win32.Teslacrypt.R176971
Acronissuspicious
McAfeeRansom-Tescrypt!5D81E04ABEA5
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agentb
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM1
RisingRansom.Tescrypt!8.3AF (CLOUD)
IkarusTrojan-Ransom.TeslaCrypt
FortinetW32/Kryptik.FXWS!tr
AVGWin32:Mutex-A [Trj]
Qihoo-360HEUR/QVM41.2.Malware.Gen

How to remove Trojan.Agent.BRKA?

Trojan.Agent.BRKA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment