Trojan

What is “Trojan-Dropper.Win32.Agent.bjykra”?

Malware Removal

The Trojan-Dropper.Win32.Agent.bjykra is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.bjykra virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Agent.bjykra?


File Info:

name: 438F6B57BF659DA9C821.mlw
path: /opt/CAPEv2/storage/binaries/573add5843e5b7979c037e748b4294d52f0d9ee980d144d5baf4636d8fb19f50
crc32: 735E5D75
md5: 438f6b57bf659da9c82106b528ff8ff6
sha1: 044f61d5fe31f62a7fc1907c1e11ba9ad1defa05
sha256: 573add5843e5b7979c037e748b4294d52f0d9ee980d144d5baf4636d8fb19f50
sha512: 2419de18aecca74c93e31e984d60f962956ce8707ab97e04c2607af768fe9fead575b2a4c00e3b3a4ca7f2244aacffa49054daf43e4b12dce191f85dd6e40bbc
ssdeep: 196608:itZpvwHiNBHSCYRW4QnjDK9dfvJms3J3JckOCFW:QpvVByDW48K9d5mkcFCFW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16476333016018472D0A60ABB6883CBF7F5397D049BECD45E63DD9E0B5C323929EA57E6
sha3_384: 4e47562fdfbdca3d181c1f38e62e68038b9cd0d5dc662e7688f92f9a68004ce22fa532bc05573c9585ca610fe52e21c1
ep_bytes: 558bec83c4f0b888534200e824f2fdff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: KRKSoft
FileDescription: Directory Lister 2.32 Installation
FileVersion: 2.32
LegalCopyright: KRKSoft
Translation: 0x0409 0x04e4

Trojan-Dropper.Win32.Agent.bjykra also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.438f6b57bf659da9
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 00544e741 )
AlibabaTrojanDropper:BAT/KillAV.ec2f6b6d
K7GWTrojan-Downloader ( 00544e741 )
Cybereasonmalicious.5fe31f
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Agent.bjykra
TencentWin32.Trojan-dropper.Agent.Pbzj
McAfee-GW-EditionBehavesLike.Win32.Wabot.vc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
IkarusTrojan-Downloader.BAT.Agent
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASSuf.3C556
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!438F6B57BF65
APEXMalicious
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
WebrootW32.Trojan.Gen

How to remove Trojan-Dropper.Win32.Agent.bjykra?

Trojan-Dropper.Win32.Agent.bjykra removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment