Trojan

VBA/TrojanDropper.Agent.BKF malicious file

Malware Removal

The VBA/TrojanDropper.Agent.BKF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBA/TrojanDropper.Agent.BKF virus can do?

  • The office file contains a macro
  • The office file contains a macro with auto execution
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VBA/TrojanDropper.Agent.BKF?


File Info:

crc32: 59B7B012
md5: 8b9a76bee8f32292b25d55383c100d2c
name: 08142020_1955816493.doc
sha1: fe63d6a4046682dabce9cc6e49bc22fbbb8399e4
sha256: a1ea10b25a1dd9165910a6859847f4bc6437f06e4651f8cc31ddf3b9d50be3c2
sha512: 9fc9740134ec8bd07b7f18ce2ab4b52136ebce65ed7d5a62493efceb545ba2a1aedd2217360f933f386716ccb5554a0700aef17949b724e7e301ab6cdaa22d15
ssdeep: 6144:qfm2kjkjxuWiyKMUsTn8XBlKqqUY1BaE8D7h6JDAm30QWIOtfXuu4MCUlmoykTHt:qfm2hVuW7VgmUYSDevEbIOE7gFywyq+K
type: Microsoft Word 2007+

Version Info:

0: [No Data]

VBA/TrojanDropper.Agent.BKF also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69442
ALYacTrojan.Downloader.DOC.Gen
AegisLabTrojan.MSOffice.SDrop.b!c
BitDefenderTrojan.GenericKDZ.69442
CyrenPP97M/Agent.IS.gen!Eldorado
SymantecW97M.Downloader
ESET-NOD32VBA/TrojanDropper.Agent.BKF
AvastSNH:Script [Dropper]
KasperskyHEUR:Trojan-Dropper.MSOffice.SDrop.gen
AlibabaTrojan:Win32/MalDoc.ali1000158
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
ViRobotW97M.S.Agent.390551
TencentWin32.Trojan.Generic.Edeg
Ad-AwareTrojan.GenericKDZ.69442
F-SecureMalware.VBS/Drop.Agent.spuju
FireEyeTrojan.GenericKDZ.69442
SophosTroj/DocDl-AAFU
SentinelOneDFI – Suspicious OPENXML
AviraVBS/Drop.Agent.xgnpa
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.bkf
MicrosoftTrojanDownloader:O97M/Qbot.PQD!MTB
ArcabitTrojan.Generic.D10F42
ZoneAlarmHEUR:Trojan-Dropper.MSOffice.SDrop.gen
GDataTrojan.GenericKDZ.69442
CynetMalicious (score: 85)
AhnLab-V3Dropper/DOC.Generic.S1281
McAfeeRDN/Generic Dropper
TACHYONSuspicious/WOX.Obfus.Gen.2
ZonerProbably Heur.W97Obfuscated
RisingDropper.Agent!8.2F (TOPIS:E0:U1psdZOoT0H)
IkarusTrojan-Dropper.VBA.Agent
FortinetVBA/Agent.BKD!tr
AVGSNH:Script [Dropper]
Qihoo-360Generic/Trojan.Dropper.be6

How to remove VBA/TrojanDropper.Agent.BKF?

VBA/TrojanDropper.Agent.BKF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment