Malware

Application.Agent.BOO (file analysis)

Malware Removal

The Application.Agent.BOO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.BOO virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Application.Agent.BOO?


File Info:

crc32: ADEE72CB
md5: ce07e32f2e9b56d8c60ef9f4ada9e352
name: Protection_ID.eXe
sha1: c93d7ad67cdc12de424c3918d16919be9e1eb13a
sha256: 26c54eb376183d508ee129531728f9e01d30f0df29d7621f390e8f0ea6a1c79c
sha512: bbb362e4c4128cf635d48f0e3f98afe3ef62b60256571d9a08b623dd07e242e151ede7334c1c3550e70527222920d2e2d05415734f60ac8964eb8f1c9be040e9
ssdeep: 24576:o8Acuv/unaHvuf94rgZ8mPdevKwTsXt+/kcV+cLug0doU0CAMX4gN:mxv/FHvufaCP81TsXt+/NNUdoIA8P
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 [PiD Team] 2002-2018
InternalName: [PiD Team] Protection ID v0.6.9.0
FileVersion: 0.6.9.0
CompanyName: [PiD Team] (CDKiller/TippeX)
ProductName: PiD Team's Protection ID v0.6.9.0
ProductVersion: 0.6.9.0
FileDescription: PiD Team's Protection ID
OriginalFilename: Protection_ID.eXe
Build: 0.6.9.0
Translation: 0x0409 0x04e4

Application.Agent.BOO also known as:

MicroWorld-eScanApplication.Agent.BOO
CAT-QuickHealTrojan.Generic
MalwarebytesTrojan.Agent
VIPRETrojan.Win32.Generic!BT
BitDefenderApplication.Agent.BOO
Cybereasonmalicious.f2e9b5
ArcabitApplication.Agent.BOO
TrendMicroTROJ_GEN.R014C0OBJ20
SymantecML.Attribute.HighConfidence
APEXMalicious
AlibabaTrojan:Application/bdhch.2ca197c1
NANO-AntivirusTrojan.Win32.Infector.fjtywq
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareApplication.Agent.BOO
SophosGeneric PUA MJ (PUA)
ComodoMalware@#2abuqs3pvj0nn
F-SecureTrojan.TR/Agent.bdhch
ZillyaTrojan.Agent.Win32.1076356
Invinceaheuristic
McAfee-GW-EditionPUP-XFB-YT
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ce07e32f2e9b56d8
EmsisoftApplication.Agent.BOO (B)
AviraTR/Agent.bdhch
MicrosoftPUA:Win32/Creprote
Endgamemalicious (high confidence)
GDataApplication.Agent.BOO
AhnLab-V3Unwanted/Win32.Agent.C2359729
McAfeePUP-XFB-YT
VBA32Trojan.MSIL.Agent
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R014C0OBJ20
YandexTrojan.Agent!2XCXHZ1sSBk
IkarusTrojan.Win32.Pepatch
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic!tr
WebrootW32.Trojan.Gen

How to remove Application.Agent.BOO?

Application.Agent.BOO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment