Spy

Spyware.Boaxxe information

Malware Removal

The Spyware.Boaxxe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Boaxxe virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Bitdefender Antivirus through the presence of a library
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristics of BetaBot / Neurevt malware
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Detects VirtualBox through the presence of a device
  • Detects VMware through the presence of a device
  • Detects VMware through the presence of a registry key
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares

How to determine Spyware.Boaxxe?


File Info:

crc32: 76AFB9C8
md5: aefec6a9857f95c75bcb7d7a88334ae2
name: AEFEC6A9857F95C75BCB7D7A88334AE2.mlw
sha1: d863134fa5b615475fd70125db144b32860ad805
sha256: 98cafcf0048b731929a01c91d518a507ceabfc0ef7eca0023227a8aa636f480a
sha512: 82054672d85fac299fc9dab6b1e593fc89a5a3257340c1041926f9a316f8069ce3b2f892fd0b4a7dbf385feea6124de88777c0198147880702e586c26dfd3ead
ssdeep: 6144:0tF2n389xh8HiWpP1Q2VlcHTYfWMUGBkvZWYTwY:qF2n389n8C81QkcH0fLUQkxX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 2016
InternalName: Chess
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Chess
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Chess
OriginalFilename: Chess.exe
Translation: 0x040f 0x04e4

Spyware.Boaxxe also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004ce30e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4993
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.364327
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Locky.84be24cf
K7GWTrojan ( 0056fe4d1 )
Cybereasonmalicious.9857f9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DBDF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Fareit-7083001-0
KasperskyTrojan-Ransom.Win32.Locky.akt
BitDefenderGen:Variant.Zusy.364327
NANO-AntivirusTrojan.Win32.Locky.evduxn
ViRobotTrojan.Win32.Locky.241664.A
SUPERAntiSpywareRansom.Locker/Variant
MicroWorld-eScanGen:Variant.Zusy.364327
TencentMalware.Win32.Gencirc.10b587a2
Ad-AwareGen:Variant.Zusy.364327
SophosML/PE-A + Mal/Zbot-UM
ComodoMalware@#3so0y9k0jgzfp
BitDefenderThetaGen:NN.ZexaF.34628.pq0@aumejaj
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_Locky.R002C0PK620
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.aefec6a9857f95c7
EmsisoftGen:Variant.Zusy.364327 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Locky.drr
AviraTR/AD.Neurevt.njjtd
MicrosoftTrojan:Win32/Neurevt.AB
ArcabitTrojan.Zusy.D58F27
AegisLabTrojan.Win32.Fareit.toYw
GDataGen:Variant.Zusy.364327
AhnLab-V3Trojan/Win32.Locky.C1492404
McAfeeGenericRXAC-VL!AEFEC6A9857F
MAXmalware (ai score=100)
MalwarebytesSpyware.Boaxxe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Locky.R002C0PK620
RisingTrojan.Betabot!8.A7DE (CLOUD)
YandexTrojan.GenAsa!ESciwHmFhRk
IkarusTrojan.Win32.Boaxxe
FortinetW32/Injector.DBDF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HgIASOkA

How to remove Spyware.Boaxxe?

Spyware.Boaxxe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment