Malware

Win32/Injector.BOAN removal guide

Malware Removal

The Win32/Injector.BOAN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BOAN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.BOAN?


File Info:

name: FAEB3DFAB6262088632C.mlw
path: /opt/CAPEv2/storage/binaries/54e38b846908e66bdf7c919ba19f5cd0ffc263b247c9b868ebaf8931af57a57a
crc32: A69897FE
md5: faeb3dfab6262088632ca5f939ed1414
sha1: b3119c8e2ac1e7ad5093b116d4eaeeaaa71608f0
sha256: 54e38b846908e66bdf7c919ba19f5cd0ffc263b247c9b868ebaf8931af57a57a
sha512: 990177b3f5ff071f158058b024d92001a546a2ce1e525e600b0a906f5152826291508f6840ee62eaeccff8a64fa45412b5f25d8cf974b2496ffe62660e5e3e81
ssdeep: 6144:JQcuOfQKktvi1vSlpV2DJdw0ot9uemTwEg0eebKrQq1YzSLZ:JQcbQ5mUKDJd/g9ueVEgM6WSLZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12474BE064FAC5803E9AC5B720796B5154581BF78FEA29A063644F36F3A30EB0C72775B
sha3_384: b629353ad87806f437674d2a5a91872fb8e7fa5eee6f749b034758e3187d395dfb840514e44cddc82e693da340c33aec
ep_bytes: 6878154000e8eeffffff000000000000
timestamp: 2014-10-23 00:17:15

Version Info:

Translation: 0x0404 0x04b0
Comments: Copyright © 1996-2013 VideoLAN and VLC Authors
CompanyName: InZtallShield
FileDescription: Telotrop sames
ProductName: Stylomas
FileVersion: 1.04.0006
ProductVersion: 1.04.0006
InternalName: Detering
OriginalFilename: Detering.exe

Win32/Injector.BOAN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.mgxr
MicroWorld-eScanGen:Heur.PonyStealer.wm2@dqq3r1db
FireEyeGeneric.mg.faeb3dfab6262088
CAT-QuickHealVirTool.VBInject.LE3
McAfeeGeneric-FAUW!FAEB3DFAB626
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Zbot.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/NetWiredRC.631cab10
K7GWTrojan ( 005863f41 )
K7AntiVirusTrojan ( 005863f41 )
VirITTrojan.Win32.Inject2.BBJU
CyrenW32/Trojan.BYWN-1020
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Injector.BOAN
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.NetWiredRC.gd
BitDefenderGen:Heur.PonyStealer.wm2@dqq3r1db
NANO-AntivirusTrojan.Win32.NetWiredRC.eefzaq
AvastWin32:Agent-AUKV [Trj]
TencentWin32.Trojan.Falsesign.Ehhz
Ad-AwareGen:Heur.PonyStealer.wm2@dqq3r1db
EmsisoftGen:Heur.PonyStealer.wm2@dqq3r1db (B)
ComodoMalware@#60l18igrso2q
DrWebTrojan.PWS.Panda.7278
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.YYDJZ
McAfee-GW-EditionGeneric-FAUW!FAEB3DFAB626
SophosMal/Generic-R + Mal/VB-ANI
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Heur.PonyStealer.wm2@dqq3r1db
JiangminBackdoor/NetWiredRC.i
WebrootW32.Infostealer.Zeus
AviraTR/Beebone.opanjfw
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Buzus
KingsoftWin32.Troj.GenericKD.v.(kcloud)
ArcabitTrojan.PonyStealer.E0D8F4
ZoneAlarmBackdoor.Win32.NetWiredRC.gd
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrand.Gen
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34212.wm2@aqq3r1db
ALYacGen:Heur.PonyStealer.wm2@dqq3r1db
TACHYONBackdoor/W32.VB-NetWiredRC.362129
VBA32Trojan.Buzus
CylanceUnsafe
TrendMicro-HouseCallTSPY_ZBOT.YYDJZ
RisingBackdoor.NetWiredRC!8.2AF (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BJGR!tr
AVGWin32:Agent-AUKV [Trj]
Cybereasonmalicious.ab6262
PandaTrj/Genetic.gen

How to remove Win32/Injector.BOAN?

Win32/Injector.BOAN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment