Threat Database Trojans Trojan.Agent.BKBU

Trojan.Agent.BKBU

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,611
Threat Level: 80 % (High)
Infected Computers: 15
First Seen: May 6, 2024
Last Seen: July 16, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.BKBU on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.Agent.BKBU?

Trojan.Agent.BKBU is a type of Trojan horse malware that can infiltrate your system without your knowledge or consent. The term "Trojan" refers to the malware's ability to disguise itself as a legitimate program or file, allowing it to bypass security measures and gain unauthorized access to your computer. The ".Agent.BKBU" part of the name suggests that it's a specific variant of Trojan horse malware, but the exact characteristics and behavior may vary.

How Trojan.Agent.BKBU Operates

Once installed, Trojan.Agent.BKBU can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. It can also create backdoors, allowing remote access to your system, or download and install additional malware. Furthermore, it may modify system settings, disable security software, or disrupt system performance.

Symptoms of Infection

Identifying the symptoms of a Trojan.Agent.BKBU infection can be challenging, as it often disguises itself as a legitimate program. However, some common indicators of infection include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You may also notice unauthorized changes to your system settings, unfamiliar programs or icons, or suspicious network activity. If you suspect that your system is infected, it's crucial to take immediate action to prevent further damage.

How to Remove Trojan.Agent.BKBU

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that all malware components have been removed.

Conclusion

Removing Trojan.Agent.BKBU from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove the malware and prevent future infections. It's essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up-to-date, using strong passwords, and avoiding suspicious downloads or links. Remember that prevention is key, and staying informed about the latest security threats can help you stay safe in the ever-evolving cyber landscape.

Analysis Report

General information

Family Name: Trojan.Agent.BKBU
Signature status: No Signature

Known Samples

MD5: 634c844243c159d958db4ab821588b87
SHA1: 97c60b357db8b5866e856182be4be2d8ee28d276
SHA256: A67BA5A6E9C99008E71FB062A976AA717AA1BECCC95CB201C9025DD3754BFF46
File Size: 50.18 KB, 50176 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 173
Potentially Malicious Blocks: 1
Whitelisted Blocks: 165
Unknown Blocks: 7

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Nl �v����(�1`1�1HO@V�A��H[u_�ze�vk`k�qw�n{b��P���������������m�Ù�����$�8წ���&M�=�S/�B1_T�Vw�`�V�R���%�������AE�Q]��D��&��$���L��@K� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陉ȁeꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Ol �v����(�1`1�1HO@V�A��H[u_�ze�vk`k�qw�n{b��P���������������m�Ù�����$�8წ���&M�=�S/�B1_T�Vw�`�V�R��9 ��%�������AE�Q]��D��&��$���L��@K� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Pl �v����(�1`1�1HO@V�A��H[u_�ze�vk`k�qw�n{b��P���������������m�Ù�����$�8წ���&M��=�S/�B1_T�Vw�`�V�R��9 ��%�������AE�Q]��D��&��$���L��@K� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...