Trojan

Trojan.Agent.BRZW removal instruction

Malware Removal

The Trojan.Agent.BRZW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BRZW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.BRZW?


File Info:

crc32: 200CB619
md5: 1d930a54791d56b6c10411570b57d2cb
name: 1D930A54791D56B6C10411570B57D2CB.mlw
sha1: f5af265bf35d0e740de05d04873b200d34bed46d
sha256: 83427ffa553f49bb627045c609b5d4e505f7129616cccce9958f61c084985676
sha512: b26f1eefb57d981dba9cac12ccfabd8440af680536e323f05b87d635fb03d89c4bffa0e6fce3ba6c43222c4755077a4de98ba6ee9defce3597e12767237f6e03
ssdeep: 6144:iBVsLLdsgLTCEUyQETKuSkPZ5PMVhewjAn6EYIW2gBsKTp0aLXWoRRBJY9HJJRws:VV3hLQET9P5UP06E+HsKl0aLNbs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2011
InternalName: Accra
FileVersion: 0.193.232.75
CompanyName: Trident Software, Ltd.
LegalTrademarks: Adored
ProductName: Asunder Wearied
ProductVersion: 0.251.64.202
FileDescription: Wholehearted Unconsidered Angina
OriginalFilename: Bitingl.EXE

Trojan.Agent.BRZW also known as:

K7AntiVirusTrojan ( 004e12bb1 )
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.60713
CynetMalicious (score: 100)
CAT-QuickHealRansom.Generic.WR4
ALYacTrojan.Agent.BRZW
CylanceUnsafe
ZillyaTrojan.CryptGen.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Kryptik.71a59ca8
K7GWTrojan ( 004e19951 )
Cybereasonmalicious.4791d5
CyrenW32/TeslaCrypt.V.gen!Eldorado
SymantecRansom.Cryptolock!g21
ESET-NOD32a variant of Win32/Kryptik.HDJG
APEXMalicious
AvastWin32:Trojan-gen
KasperskyPacked.Win32.Tpyn
BitDefenderTrojan.Agent.BRZW
NANO-AntivirusTrojan.Win32.AVKill.ebcvbg
ViRobotTrojan.Win32.TeslaCrypt.Gen.D
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.Agent.BRZW
TencentTrojan.Win32.Kryptik.jsfg
Ad-AwareTrojan.Agent.BRZW
SophosMal/Generic-R + Mal/Ransom-EM
ComodoTrojWare.Win32.Ransom.Tescrypt.BU@6b1xej
BitDefenderThetaGen:NN.ZexaF.34628.xq2@aeMEymnO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMB1
McAfee-GW-EditionRansomware-FHE!1D930A54791D
FireEyeGeneric.mg.1d930a54791d56b6
EmsisoftTrojan.Agent.BRZW (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1123144
eGambitGeneric.Malware
MicrosoftRansom:Win32/Tescrypt!rfn
ArcabitTrojan.Agent.BRZW
AegisLabHacktool.Win32.Tpyn.3!c
GDataTrojan.Agent.BRZW
TACHYONTrojan/W32.Bitman.376832.D
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeRansomware-FHE!1D930A54791D
MAXmalware (ai score=100)
VBA32BScope.Trojan.AVKill
MalwarebytesRansom.TeslaCrypt
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMB1
RisingRansom.Tescrypt!8.3AF (CLOUD)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.9242708.susgen
FortinetW32/Kryptik.ESCM!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Packed.Generic.HwcBEpsA

How to remove Trojan.Agent.BRZW?

Trojan.Agent.BRZW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment