Spy

What is “MSIL/Spy.Agent.BPU”?

Malware Removal

The MSIL/Spy.Agent.BPU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.BPU virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Spy.Agent.BPU?


File Info:

name: D5A35F64A5076157C2D1.mlw
path: /opt/CAPEv2/storage/binaries/9c509d25766a77da352ed587ff7fa61ae9e775a5ce6397ce2aa848e435bc92a8
crc32: F942EE48
md5: d5a35f64a5076157c2d1774f0e2957d3
sha1: cc823d30ae825228cdad59a1c816cf20dd30c48e
sha256: 9c509d25766a77da352ed587ff7fa61ae9e775a5ce6397ce2aa848e435bc92a8
sha512: 0d4797ff382b036644e3348e6d3eecaaf3697e7cfbb635fa8357c13f9789ab7a7599a9b1bb6024f2257785aaaa4da4314c06d1d27efd5f07cc6e21335ccd8487
ssdeep: 768:N/4qIEXwtCyTQmjP7Jz6IerTkbhYUmmTJ8uBB/UR7j2Yct:N/BIEXwtCeQmIITbhOmTjBB/URPE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC0329045EE4E221E27C6776D4F142A013B7BD56D52ACD8B7E887C493B733408A92B9F
sha3_384: 8b2ef86c73b1435fb684f2fdabdd5cff9e0e93edad90eb2c6e6d22658244fa64a95c1840da521e8fc1b6436338b83a09
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-07-05 13:41:30

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Sistema - Host attività utente
FileVersion: 1.0.0.0
InternalName: svchost.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: svchost.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Spy.Agent.BPU also known as:

LionicTrojan.Win32.Perseus.4!c
MicroWorld-eScanGen:Variant.Ser.Ursu.4764
FireEyeGen:Variant.Ser.Ursu.4764
McAfeeArtemis!D5A35F64A507
CylanceUnsafe
ZillyaTrojan.Agent.Win32.907265
SangforBackdoor.Win32.Bladabindi.ml
K7AntiVirusSpyware ( 005373761 )
AlibabaTrojan:MSIL/Generic.62fd7823
K7GWSpyware ( 005373761 )
Cybereasonmalicious.4a5076
BitDefenderThetaGen:NN.ZemsilF.34084.cm0@a80gpEh
CyrenW32/Ursu.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.BPU
Paloaltogeneric.ml
BitDefenderGen:Variant.Ser.Ursu.4764
NANO-AntivirusTrojan.Win32.MSILPerseus.fezwkg
AvastWin32:Agent-AVPP [Trj]
TencentWin32.Trojan.Generic.Wrzv
Ad-AwareGen:Variant.Ser.Ursu.4764
EmsisoftGen:Variant.Ser.Ursu.4764 (B)
ComodoMalware@#3a9r5261yp2u8
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataGen:Variant.Ser.Ursu.4764
MicrosoftBackdoor:Win32/Bladabindi!ml
ALYacGen:Variant.Ser.Ursu.4764
MAXmalware (ai score=100)
VBA32Trojan.MSIL.gen.a.1
MalwarebytesTrojan.Agent
APEXMalicious
YandexTrojan.Agent!taXY/NgX/pk
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:Agent-AVPP [Trj]
PandaTrj/GdSda.A

How to remove MSIL/Spy.Agent.BPU?

MSIL/Spy.Agent.BPU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment