Trojan

Trojan-Dropper.Win32.Agent.bjpbtq removal instruction

Malware Removal

The Trojan-Dropper.Win32.Agent.bjpbtq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.bjpbtq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Loads a driver
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rep.shopper-pro.com

How to determine Trojan-Dropper.Win32.Agent.bjpbtq?


File Info:

crc32: B1496A25
md5: e907ee39f5fb666823f8f968ac010de8
name: E907EE39F5FB666823F8F968AC010DE8.mlw
sha1: d1a48f9e2e454366cf5f08197a493a1f86146090
sha256: 0822c932d1c24698bc9a6e50f637be4308807d46820f81e59f6f16edc82b2b57
sha512: e42307a75b31fcb4941bbb68ecef41cb1d06703624eff4817eaaa70515aabd3858886fb408065b10596ca995583ff6ec5216fc2020d37936bab7271a964313b2
ssdeep: 98304:r6VON3mGlFfRCg5nj7uPTmMZImG9bfiT9LYLygvJ0KB9jO0GTWoMLN:r6VON3n9Ugnj7GLvT1ToO0GIN
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

FileVersion: 3.1.10955.2238
ProductVersion: 3.1.10955.2238
Translation: 0x0409 0x04e4

Trojan-Dropper.Win32.Agent.bjpbtq also known as:

LionicTrojan.Win32.Agent.b!c
Elasticmalicious (high confidence)
DrWebAdware.Searcher.2925
CynetMalicious (score: 100)
CAT-QuickHealAdWare.NSIS.Shopro.A
CylanceUnsafe
ZillyaDropper.Agent.Win32.212788
SangforPUP.Win32.Agent.atPQ
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/SpeedBit.066cc2f1
CyrenW32/ShopperPro.G.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/SpeedBit.G potentially unwanted
APEXMalicious
AvastNSIS:Adware-PQ [PUP]
KasperskyTrojan-Dropper.Win32.Agent.bjpbtq
NANO-AntivirusTrojan.Nsis.Drop.dfvfjd
TencentWin32.Trojan-dropper.Agent.Airn
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.e907ee39f5fb6668
WebrootPua.Shopperpro
AviraHEUR/AGEN.1129096
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitPUP.Adware.Shopro
GDataNSIS.Application.Crypted.C
AhnLab-V3PUP/Win32.CrossRider.R161183
McAfeeArtemis!E907EE39F5FB
VBA32TrojanDropper.Agent
MalwarebytesPUP.Optional.ShopperPro
SentinelOneStatic AI – Suspicious PE
AVGNSIS:Adware-PQ [PUP]
Paloaltogeneric.ml

How to remove Trojan-Dropper.Win32.Agent.bjpbtq?

Trojan-Dropper.Win32.Agent.bjpbtq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment