Threat Database Trojans Trojan.Spy.Agent.BP

Trojan.Spy.Agent.BP

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: July 14, 2025
Last Seen: February 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Spy.Agent.BP on your system indicates a potential security threat that requires immediate attention. This detection name suggests that the malware in question is a type of Trojan spyware, which is designed to gather sensitive information from the infected system without the user's knowledge or consent. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is Trojan.Spy.Agent.BP?

Trojan.Spy.Agent.BP is a detection name that implies the presence of a Trojan horse program with spyware capabilities. Trojan horses are malicious programs that disguise themselves as legitimate software, allowing them to bypass security measures and gain access to the system. The "Spy" component of the name suggests that this malware is designed to gather sensitive information, such as login credentials, browsing history, or other personal data.

How Trojan.Spy.Agent.BP Operates

Once installed on the system, Trojan.Spy.Agent.BP can operate in various ways to achieve its goals. It may create a backdoor to allow remote access to the system, enabling the attacker to control the system, steal data, or install additional malware. It can also modify system settings, disable security software, or intercept communication between the system and the internet. The malware may use various techniques to evade detection, such as code obfuscation, encryption, or hiding in legitimate system processes.

Symptoms of Infection

Systems infected with Trojan.Spy.Agent.BP may exhibit various symptoms, including unusual system behavior, slow performance, or unexpected crashes. The malware may also cause changes to browser settings, such as modifying the homepage or search engine, or displaying unwanted advertisements. In some cases, the malware may attempt to steal sensitive information, such as login credentials or credit card numbers, which can lead to identity theft or financial loss.

  • Unexplained changes to system settings or browser configurations
  • Unexpected pop-ups, advertisements, or browser redirects
  • Slow system performance or frequent crashes
  • Unusual network activity or suspicious login attempts

How to Remove Trojan.Spy.Agent.BP

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and remove any detected threats.
  3. Uninstall any suspicious programs or software that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Spy.Agent.BP from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable security software, you can help ensure the complete removal of the threat and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system and personal data from malware threats.

Analysis Report

General information

Family Name: Trojan.Spy.Agent.BP
Signature status: No Signature

Known Samples

MD5: 535a9b870f9ef872b6ed8fef3beab8da
SHA1: c4664dbbce504b538c4ac0706d690916283c47d5
SHA256: 8201551520D88DA852863C340230DA37FEFF7E3F0A99D983C29BAF315AF37A49
File Size: 147.97 KB, 147968 bytes
MD5: 7a3a14b78bca9a80e1b67b7a4c8c2eda
SHA1: 7192c6aea68aa66a3757b078e1f8552a153e25ed
SHA256: 6BEEEFFD74398FB4435004503348C210C838F3D6F955B7DBA54A85E9AE5CEAB3
File Size: 137.22 KB, 137216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • VirtualQueryEx
  • x64

Block Information

Total Blocks: 54
Potentially Malicious Blocks: 48
Whitelisted Blocks: 2
Unknown Blocks: 4

Visual Map

x x x x 0 x ? x x x x x x x x x x x x x x x x x x x x x x x ? x x ? x 0 ? x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\edge\blbeacon::failed_count RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::state  RegNtPreCreateKey
HKCU\software\microsoft\edge\thirdparty::statuscodes (NULL) RegNtPreCreateKey
HKCU\software\microsoft\edge\thirdparty::statuscodes  RegNtPreCreateKey
HKCU\software\microsoft\edge\elfbeacon::version 143.0.3650.80 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
Show More
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSendRequest
User Data Access
  • GetComputerName
  • GetUserName
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Terminate
  • TerminateProcess
Anti Debug
  • OutputDebugString

Shell Command Execution

"C:\Program Files\Google\Chrome\Application\chrome.exe" --headless --log-level=3
"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --headless --log-level=3
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --headless --log-level=3

Related Posts

Trending

Most Viewed

Loading...