Trojan

Should I remove “Trojan.Agent.BOBA”?

Malware Removal

The Trojan.Agent.BOBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BOBA virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the NetWire malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.BOBA?


File Info:

name: 8B4619872687D62F4E88.mlw
path: /opt/CAPEv2/storage/binaries/f220d4b5ec4a2f3a7136d6416c0f7aa96defcfb69b53d78768c8b6dd20cbf8a4
crc32: D59CD0D2
md5: 8b4619872687d62f4e88201b47e674f4
sha1: 205d418565c92d7d72403fa07adfc854e6a41427
sha256: f220d4b5ec4a2f3a7136d6416c0f7aa96defcfb69b53d78768c8b6dd20cbf8a4
sha512: c53b1b413b34912319e595bfe2ad2f2d65c320be73e560f746d2a8944a019c336973548cce507ddb88b5abf0a31cdf5426429dcd84ddece5105a7323348ead3d
ssdeep: 1536:Jr/zIEc9uQ1q1vD9qrPP+r4MrdN/F+Xs6ibNqiRGWkxuABpWTF:Jr/zIEyQIrPP+r4MrdN/086ibgqGWkhe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F83C719FA0BE0F2EE4E5D7162CBF6AF0B786920D864CE41DF840D43EA53D536219B94
sha3_384: 44ba8e76e4ca6b704610832ce83c89e57b7d7acda77ebdfe6b610b59e2ec5e53d56afc1c4bbff7967818f7991c35e0d4
ep_bytes: 55b83c100000575653e86c06010029c4
timestamp: 2015-04-04 14:56:51

Version Info:

0: [No Data]

Trojan.Agent.BOBA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NetWiredRC.tnGH
MicroWorld-eScanTrojan.Agent.BOBA
ClamAVWin.Dropper.NetWire-9781821-0
FireEyeGeneric.mg.8b4619872687d62f
CAT-QuickHealBackdoor.Netwiredrc.A4
ALYacTrojan.Agent.BOBA
MalwarebytesWeecnaw.Spyware.Stealer.DDS
ZillyaTrojan.Recam.Win32.191
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaBackdoor:Win32/NetWiredRC.7ad5a5ed
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.72687d
ArcabitTrojan.Agent.BOBA
BaiduWin32.Trojan-Spy.Weecnaw.a
VirITTrojan.Win32.Generic.DBV
CyrenW32/Fsysna.C.gen!Eldorado
SymantecSMG.Heur!gen
ElasticWindows.Trojan.Netwire
ESET-NOD32Win32/Spy.Weecnaw.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.NetWiredRC.bfi
BitDefenderTrojan.Agent.BOBA
NANO-AntivirusTrojan.Win32.Recam.dywvho
SUPERAntiSpywareBackdoor.NetWired
AvastMulti:Wirenet-B [Trj]
TencentMalware.Win32.Gencirc.10b0a14a
TACHYONTrojan-Spy/W32.Recam.86016
EmsisoftTrojan.Agent.BOBA (B)
F-SecureTrojan.TR/Spy.Gen
DrWebBackDoor.Wirenet.96
VIPRETrojan.Agent.BOBA
TrendMicroTrojanSpy.Win32.WEECNAW.SMUM
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
Trapminemalicious.high.ml.score
SophosTroj/Netwire-AN
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Recam.by
WebrootTrojan.Dropper.Gen
AviraTR/Spy.Gen
Antiy-AVLTrojan[Spy]/Win32.Recam
XcitiumBackdoor.Win32.NetWiredRC.AV@8bjx26
MicrosoftBackdoor:Win32/NetWiredRC.C
ViRobotTrojan.Win32.Z.Netwiredrc.86016.A
ZoneAlarmBackdoor.Win32.NetWiredRC.bfi
GDataTrojan.Agent.BOBA
GoogleDetected
AhnLab-V3Trojan/Win32.MDA.R149922
Acronissuspicious
McAfeeTrojan-FISN!8B4619872687
MAXmalware (ai score=100)
VBA32BScope.TrojanSpy.Loyeetro
Cylanceunsafe
PandaTrj/CredentialsStealer.B
TrendMicro-HouseCallTrojanSpy.Win32.WEECNAW.SMUM
RisingBackdoor.NetWire!1.A18E (CLASSIC)
YandexTrojan.GenAsa!E9k0oOaJ9aU
IkarusBackdoor.Win32.NetWiredRC
MaxSecureTrojan.Malware.8292391.susgen
FortinetW32/Inject.AVQ!tr
BitDefenderThetaAI:Packer.7BBDDDB31E
AVGMulti:Wirenet-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.BOBA?

Trojan.Agent.BOBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment