Malware

Should I remove “Win32/Pterodo.BGJ”?

Malware Removal

The Win32/Pterodo.BGJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Pterodo.BGJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A script process created a new process
  • A script process initiated network activity
  • Attempts to modify proxy settings
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Pterodo.BGJ?


File Info:

name: 45FF80BCB9BB2EB7C625.mlw
path: /opt/CAPEv2/storage/binaries/20c0a18c2aed543409bb5de9cc1a2ff6374e244e6de0c4b529eac84a68d5901b
crc32: 4F5C347F
md5: 45ff80bcb9bb2eb7c625333c71242e81
sha1: 47e1de09a351f3dc293479b8aded9a4682dd4c1f
sha256: 20c0a18c2aed543409bb5de9cc1a2ff6374e244e6de0c4b529eac84a68d5901b
sha512: 19ddbd2b4855210b8190aebaecaf5979cba9d3cbb29f2dedc31a126fdddcd8175f934dd3245b7b4366928b9df71360ceee7e98051e2a4bf8fa783b966a718718
ssdeep: 3072:29Y9qKehdxneOjpoauomgdcdLoqdwS5ex2TXL8NLLWl:aY9qFxfpo4hI38NWl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187C37C5178D0C472E57629334C64DAB48A2DF9704E619FAB37CC163F0F34281DE6A9AB
sha3_384: 51c1d910128c18bc1eb5f283148c4849ebacc5de7be2327dcd7055d4bc93f703fd203f2cde8db8fd26f0d8f0bcf5ab1f
ep_bytes: e8f5040000e974feffff558becf64508
timestamp: 2021-10-29 06:35:58

Version Info:

0: [No Data]

Win32/Pterodo.BGJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.VBS.SAgent.4!c
MicroWorld-eScanGen:Variant.Adware.Symmi.10406
McAfeeRDN/Generic.hbg
CylanceUnsafe
K7AntiVirusTrojan ( 00589ba41 )
BitDefenderGen:Variant.Adware.Symmi.10406
K7GWTrojan ( 00589ba41 )
Cybereasonmalicious.cb9bb2
ESET-NOD32a variant of Win32/Pterodo.BGJ
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.VBS.SAgent.gen
RisingTrojan.Generic@ML.82 (RDMK:Aix8QLWp8A50f9aXs5fg9w)
Ad-AwareGen:Variant.Adware.Symmi.10406
EmsisoftGen:Variant.Adware.Symmi.10406 (B)
DrWebTrojan.MulDrop19.10645
TrendMicroTROJ_GEN.R002C0PL321
McAfee-GW-EditionRDN/Generic.hbg
FireEyeGeneric.mg.45ff80bcb9bb2eb7
GDataGen:Variant.Adware.Symmi.10406
AviraTR/Pterodo.pubrg
Antiy-AVLTrojan/Generic.ASMalwS.34E18A2
ArcabitTrojan.Adware.Symmi.D28A6
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Adware/Win.Generic.C4808035
ALYacGen:Variant.Adware.Symmi.10406
MAXmalware (ai score=68)
TrendMicro-HouseCallTROJ_GEN.R002C0PL321
TencentWin32.Trojan.Adware.Pfjz
FortinetRiskware/Pterodo
BitDefenderThetaGen:NN.ZexaF.34062.hqY@aeBjC@
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Pterodo.BGJ?

Win32/Pterodo.BGJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment