Trojan

Trojan.VBS.Agent.bdu malicious file

Malware Removal

The Trojan.VBS.Agent.bdu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VBS.Agent.bdu virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.VBS.Agent.bdu?


File Info:

name: ECA21E7638208534F567.mlw
path: /opt/CAPEv2/storage/binaries/aece5fa34ef2a75f82f720b1dfbedc968c308b20b58d7fdd13ed16784ec8327a
crc32: 95D47665
md5: eca21e7638208534f567da165050b76c
sha1: 672f799060c080baa2ccdc403bab56a632a66ac4
sha256: aece5fa34ef2a75f82f720b1dfbedc968c308b20b58d7fdd13ed16784ec8327a
sha512: f74a57e754ce9eeb0990d3ed0be94ddfe7c3d8befaeffca4dc91dba30a9df1a70bddc214fe1d9ae453aa9de3231f2e459f93d0ed266f75fec7d2afc0348643e4
ssdeep: 196608:SKqN16Li5Zew9oSVinMGyYUIje45279lgFAu8ekDkvdDbfQwzq5AqUzFThp:SX6KZ3mSuryJIjc9wAu8e6GdDMwztqGZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172A633D95248DE9BCEA613F00A73DE3C4E6CFD61183611BC862BB1EEDE1325450B568B
sha3_384: c20afa8e88bf964aca6bfa3f3718d3188fe1c420f82aa2a63e5efd568610b8aaa176e15233ce2440089850291fa2d496
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-09-18 13:57:39

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: RisenLauncher.exe.exe
LegalCopyright:
OriginalFilename: RisenLauncher.exe.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.VBS.Agent.bdu also known as:

LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanIL:Trojan.MSILZilla.19239
FireEyeGeneric.mg.eca21e7638208534
CAT-QuickHealTrojan.GenericFC.S30155648
McAfeeArtemis!ECA21E763820
MalwarebytesSpyware.PasswordStealer.MSIL.Generic
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojanPSW:MSIL/XWormRAT.20ff2723
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitIL:Trojan.MSILZilla.D4B27
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FOV
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Packed.Msilzilla-10008147-0
KasperskyTrojan.VBS.Agent.bdu
BitDefenderIL:Trojan.MSILZilla.19239
EmsisoftIL:Trojan.MSILZilla.19239 (B)
DrWebTrojan.MulDropNET.65
TrendMicroTROJ_GEN.R002C0DII23
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Drop.Agent.elvba
MAXmalware (ai score=85)
MicrosoftTrojan:MSIL/XWormRAT.A!MTB
ViRobotTrojan.Win.Z.Agent.10142720
ZoneAlarmHEUR:Trojan-PSW.MSIL.Coins.gen
GDataIL:Trojan.MSILZilla.19239
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5052738
BitDefenderThetaGen:NN.ZemsilF.36662.@p0@aaV6VK
ALYacIL:Trojan.MSILZilla.19239
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DII23
RisingStealer.Coins!8.133E9 (CLOUD)
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.FOV!tr
Cybereasonmalicious.060c08
DeepInstinctMALICIOUS

How to remove Trojan.VBS.Agent.bdu?

Trojan.VBS.Agent.bdu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment