Malware

Win32/Agent_AGen.BOA (file analysis)

Malware Removal

The Win32/Agent_AGen.BOA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.BOA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent_AGen.BOA?


File Info:

name: D8CA866EFC327910C74B.mlw
path: /opt/CAPEv2/storage/binaries/8ae2887b11f3f6362640b8dd67a076c5e6a5d132f9a9d2581c65ff153782719b
crc32: 1F22EE3A
md5: d8ca866efc327910c74bf64003839b34
sha1: 00543d6449ee57a3fde9f4d7b0eceafeb759d59f
sha256: 8ae2887b11f3f6362640b8dd67a076c5e6a5d132f9a9d2581c65ff153782719b
sha512: d89a6d53cf80c0c4b24fcbb1350daac7f5a70cd8e288748cf4074e73f158e52ddc9f2aac60160bbcafd19730aa6497151a363872995f5a6e7e18c7d73b2b602a
ssdeep: 1536:ktW4Q3ece1YMugSs8/5kvJzhw+r+lmc4Csgh9vGrt7JplAHTq:kY4Q3gY/Xkv5hwihyvatDlQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7738E63B88544B7D693013105A46B24FBFF6B386935DDA7CB1849C6AC794C2723B2CA
sha3_384: 91088c9ddb7efde729da30b9afe9bdbd5420c9f1ce89082149e386c1e8e575aa44b06fb11f7559a315ffd6280ac10813
ep_bytes: 6033c08d480d50e2fd8bec648b403078
timestamp: 2007-10-22 13:41:55

Version Info:

0: [No Data]

Win32/Agent_AGen.BOA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.DNSChanger.l02C
MicroWorld-eScanTrojan.DNSChanger.BX
ClamAVWin.Trojan.DNSChanger-167
FireEyeGeneric.mg.d8ca866efc327910
McAfeeDNSChanger.ee.gen
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00021afd1 )
AlibabaTrojan:Win32/DNSChanger.8cf16569
K7GWTrojan ( 00021afd1 )
Cybereasonmalicious.efc327
BitDefenderThetaGen:NN.ZexaF.36348.eiW@aSvSZdc
CyrenW32/Trojan2.AEBE
SymantecTrojan.Packed.7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.BOA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.DNSChanger.aum
BitDefenderTrojan.DNSChanger.BX
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SUPERAntiSpywareTrojan.Unclassified/K-Series-A
AvastWin32:DNSChanger-TL [Trj]
TencentTrojan-DL.Win32.Zlob.k
EmsisoftTrojan.DNSChanger.BX (B)
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.DnsChange
VIPRETrojan.DNSChanger.BX
TrendMicroTROJ_DNSCHANG.AM
McAfee-GW-EditionBehavesLike.Win32.Infected.lh
Trapminemalicious.high.ml.score
SophosMal/Behav-010
SentinelOneStatic AI – Malicious PE
GDataTrojan.DNSChanger.BX
JiangminTrojan/DNSChanger.fww
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan/Win32.DNSChanger
XcitiumTrojWare.Win32.DNSChanger.AUM@l9a32
ArcabitTrojan.DNSChanger.BX
ViRobotTrojan.Win.Z.Dnschanger.76288.W
ZoneAlarmTrojan.Win32.DNSChanger.aum
MicrosoftVirTool:Win32/Obfuscator.S
GoogleDetected
AhnLab-V3Win-Trojan/Dnschanger.90267
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.DNSChanger.BX
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DNSCHANG.AM
RisingTrojan.Zlob!1.A07E (CLASSIC)
YandexPacked/ZCrypt
IkarusTrojan.DNSChanger
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.AAC!tr
AVGWin32:DNSChanger-TL [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.BOA?

Win32/Agent_AGen.BOA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment