Trojan

Win32/TrojanDownloader.Agent.BBP malicious file

Malware Removal

The Win32/TrojanDownloader.Agent.BBP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.BBP virus can do?

  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates Zeus (Banking Trojan) mutexes

How to determine Win32/TrojanDownloader.Agent.BBP?


File Info:

name: B1418568BCF9D9B305E1.mlw
path: /opt/CAPEv2/storage/binaries/ca6a0561835498833e62033881f2b9d5c7f1b6103e26e1fe48e7cafa1b593c82
crc32: 5A4FFA2B
md5: b1418568bcf9d9b305e182955d5268f5
sha1: 1c6a6d90d116d9be2000f9cf629b83d9c7e67399
sha256: ca6a0561835498833e62033881f2b9d5c7f1b6103e26e1fe48e7cafa1b593c82
sha512: f47dd38a625d4f14013e4f4c7fc368233e3480d4ba124a2e267a2dbd2ca4cc2d5c30700bd009b24b115d387a636459e20830741e55210a1c99b5c2a102702e96
ssdeep: 24576:lBUZ4C4cCSEukwq/Ar5K3BBUnjxoyd+BDR47SivS0ba:laZ49cqukwq/7KnB44miv6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C352342A79D09A7F15109754850DD23AFB8F2604C3A5DE2EFCD8EC74B92D6704BE2A3
sha3_384: c9d3968d87de2305b12dfe87ac8af26539a4614780e4b9973a69912c633fda77738e4bb06c16dd4e7e1622009ac79c08
ep_bytes: 558bec81ec380400005356576a21e8ea
timestamp: 2006-11-11 18:37:11

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.BBP also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BCB
CAT-QuickHealTrojanpws.Zbot.26928
ALYacTrojan.Agent.BCB
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.8bcf9d
CyrenW32/Injector.A.gen!Eldorado
ESET-NOD32Win32/TrojanDownloader.Agent.BBP
APEXMalicious
ClamAVWin.Malware.Zeus-9785249-1
KasperskyTrojan-Spy.Win32.Zbot.adu
BitDefenderTrojan.Agent.BCB
NANO-AntivirusTrojan.Win32.Zbot.bcaxop
AvastWin32:Agent-EDZ [Trj]
TencentMalware.Win32.Gencirc.11b0c042
Ad-AwareTrojan.Agent.BCB
EmsisoftTrojan.Agent.BCB (B)
ComodoTrojWare.Win32.TrojanDownloader.Agent.BBP@34q7
DrWebTrojan.PWS.Tanspy
ZillyaTrojan.Zbot.Win32.207769
TrendMicroTROJ_AGENT.AEQB
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b1418568bcf9d9b3
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BCB
JiangminTrojanSpy.Zbot.almv
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
ArcabitTrojan.Agent.BCB
MicrosoftTrojanDownloader:Win32/Agent
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Small.C4168175
Acronissuspicious
McAfeeProxy-Agent.bd
VBA32Trojan.Inject.01376
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_AGENT.AEQB
RisingTrojan.Agent.yif (CLASSIC)
YandexTrojanSpy.Zbot!OlCFNn+9VSs
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Zbot.PZ!tr.spy
BitDefenderThetaAI:Packer.EEBAFD021E
AVGWin32:Agent-EDZ [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/TrojanDownloader.Agent.BBP?

Win32/TrojanDownloader.Agent.BBP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment