Trojan

Should I remove “VB:Trojan.VBA.Agent.BGI”?

Malware Removal

The VB:Trojan.VBA.Agent.BGI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VB:Trojan.VBA.Agent.BGI virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine VB:Trojan.VBA.Agent.BGI?


File Info:

crc32: E827DC16
md5: bd0b2531ba513e3202a67539eb4e2271
name: upload_file
sha1: 6801c420d880e5455ca9e56b5d06299dfa9b129d
sha256: 13c77da9bbdaea66303dfe4cfcb8b5a9f8eae8d46f1e710ab6574c73b2c1d91e
sha512: 15a9b967719738444e4350b4d7727a15c715edc579affba656e469dafae91e25ea18684ffe44cb4db0c6ef761a79d3e07ca7b9c9fb2e15a5ca28662f1dde5eee
ssdeep: 3072:NMj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkN4Oqi8DKwW9CRB:KHgtEWPsL/aTyT9GkN4OqirwWoRB
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Suscipit., Author: Julien Morin, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Aug 10 23:42:00 2020, Last Saved Time/Date: Mon Aug 10 23:42:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 23, Security: 0

Version Info:

0: [No Data]

VB:Trojan.VBA.Agent.BGI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVB:Trojan.VBA.Agent.BGI
FireEyeVB:Trojan.VBA.Agent.BGI
McAfeeW97M/Dropper.gc
SymantecW97M.Downloader
ESET-NOD32VBA/TrojanDownloader.Agent.UAY
AvastScript:SNH-gen [Trj]
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BGI
AegisLabTrojan.MSOffice.SAgent.4!c
TencentHeur.Macro.Generic.f.6c5dbbc2
Ad-AwareVB:Trojan.VBA.Agent.BGI
EmsisoftVB:Trojan.VBA.Agent.BGI (B)
F-SecureMalware.W97M/Agent.5505611
DrWebExploit.Siggen2.16640
TrendMicroPossible_SMPOWLOADBB4
FortinetVBA/Agent.BGA!tr.dldr
SophosMal/DocDl-L
IkarusTrojan-Downloader.VBA.Emotet
CyrenW97M/Downldr.IE.gen!Eldorado
AviraW97M/Agent.5505611
MAXmalware (ai score=100)
ArcabitVB:Trojan.VBA.Agent.BGI
AhnLab-V3Downloader/DOC.Emotet.S1072
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
CynetMalicious (score: 85)
ALYacTrojan.Downloader.DOC.Gen
TACHYONSuspicious/W97M.Obfus.Gen.1
ZonerProbably Heur.W97Obfuscated
RisingMalware.ObfusVBA@ML.99 (VBA)
GDataVB:Trojan.VBA.Agent.BGI
AVGScript:SNH-gen [Trj]
Qihoo-360Generic/Trojan.3b4

How to remove VB:Trojan.VBA.Agent.BGI?

VB:Trojan.VBA.Agent.BGI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment