Adware

Should I remove “Adware.Hebogo.A3”?

Malware Removal

The Adware.Hebogo.A3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Hebogo.A3 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Adware.Hebogo.A3?


File Info:

name: 3227A071E3B375C5D6B4.mlw
path: /opt/CAPEv2/storage/binaries/7bb0acf1269ea5d66cc5da2cedb86bb2c091827d7df93e2783b8098eec0df68e
crc32: BD969AFC
md5: 3227a071e3b375c5d6b4031f0d174183
sha1: c05d04036442af8c585a2793343133cb13769644
sha256: 7bb0acf1269ea5d66cc5da2cedb86bb2c091827d7df93e2783b8098eec0df68e
sha512: 07b8a27256228a8ced387ef3669f0fe0995211406bda2b90c00e37b96c1e04f353489089aef175d8a4b9e68120e3e3b8dc0848598750ce8484f3ba638f4778ab
ssdeep: 1536:MZTPudXlM6L3wZPndM8QceD/VLdYR9GimSp6/pnLsbf:MZ6dXl7L3wZPScKVLUIH/pnLsb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6C35032BE109035F4C14975392AB217B93E2E719605AC5FF3938B6426B235B36F5B0B
sha3_384: f6e279f0e10196cd7323069f1ddffe5e24a47e1f02b8627086301a272beb59b9608c62a79d053350f4c530e254baef91
ep_bytes: 686c2c4000e8eeffffff000000000000
timestamp: 2021-11-03 00:34:01

Version Info:

Translation: 0x0412 0x04b0
CompanyName: Micronames Corp.
ProductName: Smart Service
FileVersion: 2.00.1441
ProductVersion: 2.00.1441
InternalName: DtsGuardCare
OriginalFilename: DtsGuardCare.exe

Adware.Hebogo.A3 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47536125
CAT-QuickHealAdware.Hebogo.A3
McAfeePUP-FMT
CylanceUnsafe
ZillyaAdware.Hebogo.Win32.3520
K7AntiVirusAdware ( 004f50c21 )
K7GWAdware ( 004f50c21 )
Cybereasonmalicious.1e3b37
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Hebogo.D
ClamAVWin.Malware.Hebogo-9872088-0
BitDefenderTrojan.GenericKD.47536125
AvastWin32:AdwareX-gen [Adw]
Ad-AwareTrojan.GenericKD.47536125
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt.Win32.AdWare.Hebogo.STA@4rf3fi
DrWebAdware.Hebogo.33
McAfee-GW-EditionPUP-FMT
FireEyeGeneric.mg.3227a071e3b375c5
EmsisoftTrojan.GenericKD.47536125 (B)
IkarusTrojan-Clicker.Win32.VB.DN
GDataTrojan.GenericKD.47536125
AviraTR/VB.Downloader.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.3370D65
ArcabitTrojan.Generic.D2D557FD
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Hebogo.R190939
ALYacTrojan.GenericKD.47536125
MalwarebytesAdware.MicroNames
YandexTrojan.GenAsa!/eWnFY12BPo
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Hebogo
AVGWin32:AdwareX-gen [Adw]
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Adware.Hebogo.A3?

Adware.Hebogo.A3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment