Malware

Application.Agent.BOI removal guide

Malware Removal

The Application.Agent.BOI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.BOI virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Application.Agent.BOI?


File Info:

name: A349F8C763CBEC045671.mlw
path: /opt/CAPEv2/storage/binaries/5eb53e7deedadfc18088aa142753a94831886e06bb71673babae523bc19a2e13
crc32: 162ED415
md5: a349f8c763cbec0456710dc3b562d787
sha1: cf81bbee8fb2f11ee7760106b75feb70e5f64b51
sha256: 5eb53e7deedadfc18088aa142753a94831886e06bb71673babae523bc19a2e13
sha512: 01ec1fe66c2886e48fd469e2aafdb43a759e027804f207a3accdc1377f0d7bc8b4550221f830d00d8701eb8b9c1ad188c97ffed9d932d7c0abe25c9dfa85347f
ssdeep: 3072:DrAVguiZxHF02SOacgAf+9mzB7y7YRguXtf:DWgVZ1vGAfL1X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3F38C0237C1C070EAE7023109B89B66997DFD714BB049D7B7984B1E6DB06D0AB36B67
sha3_384: 50afe749f36ad2a42bc5170b9d74d18ab7da1ff1bdc2cabab1cbd24516795f0b49c95122732d07ec26188ee98e6afd0e
ep_bytes: e8a6730000e97ffeffff558bec568b75
timestamp: 2016-09-23 08:27:17

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.9.0.1
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.9.0.1
Comments:
Translation: 0x0409 0x04b0

Application.Agent.BOI also known as:

LionicAdware.Win32.Machaer.2!c
Elasticmalicious (high confidence)
DrWebAdware.Downware.17838
MicroWorld-eScanApplication.Agent.BOI
FireEyeApplication.Agent.BOI
CAT-QuickHealAdware.MailRu.S72436
McAfeePUP-FYD
MalwarebytesPUP.Optional.RussAd
K7AntiVirusUnwanted-Program ( 004fffcd1 )
AlibabaAdWare:Win32/MailRu.20167f4c
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.763cbe
CyrenW32/S-e83a6442!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/MailRu.R potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PKR21
ClamAVWin.Malware.Mailru-6804211-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderApplication.Agent.BOI
SUPERAntiSpywarePUP.MailRU/Variant
AvastFileRepMetagen [PUP]
TencentTrojan.Win32.Reflo.ya
Ad-AwareApplication.Agent.BOI
EmsisoftApplication.AdMail (A)
ComodoApplication.Win32.MailRu.EC@6mwxfg
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
SophosMail.ru Downloader (PUA)
IkarusPUA.MailRu
JiangminAdWare.Machaer.bm
Antiy-AVLTrojan/Generic.ASBOL.A8F1
MicrosoftProgram:Win32/Wacapew.C!ml
ViRobotTrojan.Win32.Agent.158352
GDataWin32.Application.MailRu.A
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.MailRu.X2108
VBA32Adware.Downware
ALYacApplication.Agent.BOI
MAXmalware (ai score=74)
RisingPUF.MailRu!1.A9B5 (CLASSIC)
YandexRiskware.Agent!l+wV+lSL8Kg
SentinelOneStatic AI – Malicious PE
FortinetW32/MailRu.M!tr
AVGFileRepMetagen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Application.Agent.BOI?

Application.Agent.BOI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment