Malware

GenPack:Application.Agent.BPO removal guide

Malware Removal

The GenPack:Application.Agent.BPO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Application.Agent.BPO virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine GenPack:Application.Agent.BPO?


File Info:

name: 68AC1C2BA03851CF2674.mlw
path: /opt/CAPEv2/storage/binaries/e3da75c2729a82c263c90b2282caef211663e175b8e951f2709f785bb5faaca2
crc32: 964F1A73
md5: 68ac1c2ba03851cf26745aa6ae62eeb7
sha1: 110c6197d7bf9021ca8da9ca076350457c44d4db
sha256: e3da75c2729a82c263c90b2282caef211663e175b8e951f2709f785bb5faaca2
sha512: 6d204328b5a27d936b05dad071828a9191df8dc25c4b75941ceea5c1dc11a2ee0e1697583f1fd8562318ee3186b2c642baefa602db0a3b2f1874ab20c5bb781d
ssdeep: 1536:oO/C7f7XItDLZz79pJkjnuUyb6IxRBUEHkW3gg48Z1Kd:K7f78DLvyAb6IxBHJgqZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15F6302776FB55F75ED0BE174038827915E3291B8B690D9A3B820947CFF2EAA9230814D
sha3_384: 375049f8ee60c4f59aeaeeb056afb68d3228ddc4a09f4826d83dbb86e699f912c66c28d5cfa52472a18c0fc0730e4b50
ep_bytes: 60be158041008dbeeb8ffeff57eb0b90
timestamp: 2014-07-01 18:02:13

Version Info:

0: [No Data]

GenPack:Application.Agent.BPO also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Snojan.3!c
AVGWin32:Malware-gen
MicroWorld-eScanGenPack:Application.Agent.BPO
FireEyeGenPack:Application.Agent.BPO
SkyhighBehavesLike.Win32.BadFile.kc
McAfeeArtemis!68AC1C2BA038
MalwarebytesGeneric.Malware/Suspicious
VIPREGenPack:Application.Agent.BPO
SangforTrojan.Win32.Agent.Vges
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Cymt-10023133-0
KasperskyHEUR:Flooder.Win32.CoreWarrior.a
BitDefenderGenPack:Application.Agent.BPO
NANO-AntivirusTrojan.Win32.Snojan.jqzopm
AvastWin32:Malware-gen
EmsisoftGenPack:Application.Agent.BPO (B)
DrWebTool.Snojan.1
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
JiangminDownloader.Snojan.adp
MAXmalware (ai score=77)
Antiy-AVLHackTool[Flooder]/Win32.CoreWarrior
MicrosoftTrojanDownloader:Win32/Nemucod
XcitiumTrojWare.Win32.Snojan.B@7h1cjp
ArcabitGenPack:Application.Agent.BPO
ZoneAlarmHEUR:Flooder.Win32.CoreWarrior.a
GDataGenPack:Application.Agent.BPO
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36802.emW@aeb!vVo
ALYacGenPack:Application.Agent.BPO
Cylanceunsafe
RisingDownloader.Snojan!8.ECDD (TFE:5:V47YrAkOYKG)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Snojan
DeepInstinctMALICIOUS
alibabacloudDDoS:Win/Nemucod

How to remove GenPack:Application.Agent.BPO?

GenPack:Application.Agent.BPO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment