Adware

Adware.Hebogo.SUF (file analysis)

Malware Removal

The Adware.Hebogo.SUF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Hebogo.SUF virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

hostserver.kr
itemprice.kr
maketop.kr
mainserver.kr
duzip.com
korserver.com
domainserver.co.kr
makevalue.com

How to determine Adware.Hebogo.SUF?


File Info:

crc32: 0B51E0D2
md5: d90d4f053a3fc26b645db1cf5e6e2e27
name: drtcheck.exe
sha1: 0bc5efe7c81c12fc9c4b2680fe9a29c788e17e44
sha256: e3d236d5c3a6dc908321451d56e9c6614da06bf222c4bedb27413f76dfa888f2
sha512: cb83d37c116e90cda08995ef32b81a60785d5bda3b88d3dfdeefa1a97a2cd15c1a079bfa59b63e182c189bd8cb3984b97b2ea9f0a250f205d2a4153feb89e652
ssdeep: 24576:zcgCYQ1LGum4sx8Kofd/uV+wfK+7fGJUU708L3Tm:ogCh1LGumhuW+iK+zGiUJrTm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2009 Indigo Rose Corporation
InternalName: suf80_launch
FileVersion: 8.2.1.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory 8.0
ProductName: Setup Factory 8.0 Runtime
ProductVersion: 8.2.1.0
FileDescription: Setup Application
OriginalFilename: suf80_launch.exe
Translation: 0x0409 0x04e4

Adware.Hebogo.SUF also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Razy.540364
FireEyeGen:Variant.Razy.540364
Qihoo-360QVM41.1.Malware.Gen
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004db7621 )
BitDefenderGen:Variant.Razy.540364
K7GWAdware ( 004db7621 )
Cybereasonmalicious.53a3fc
TrendMicro-HouseCallHV_HEBOGO_CA2333AA.TOMC
AvastWin32:Hebogo-A [Adw]
GDataGen:Variant.Johnnie.186177
KasperskyTrojan-Downloader.Win32.MultiDL.rsc
APEXMalicious
Ad-AwareGen:Variant.Razy.540364
DrWebAdware.Hebogo.28
Invinceaheuristic
McAfee-GW-EditionPUP-FMZ
EmsisoftGen:Variant.Razy.540364 (B)
CyrenW32/S-6e14229d!Eldorado
WebrootW32.Malware.Gen
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.MicroNames
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D83ECC, Trojan.Johnnie.D2D7E6, Trojan.Adware.Graftor.D1D86D, Trojan.Johnnie.D2D741
SUPERAntiSpywareAdware.Hebogo/Variant
ZoneAlarmTrojan-Downloader.Win32.MultiDL.rsc
MicrosoftPUA:Win32/MicroNames
McAfeePUP-FMZ
VBA32BScope.Backdoor.VB
MalwarebytesAdware.Hebogo.SUF
ESET-NOD32a variant of Win32/Adware.Hebogo.B
TencentWin32.Trojan.Razy.Wptd
eGambitUnsafe.AI_Score_100%
AVGWin32:Hebogo-A [Adw]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Adware.Hebogo.SUF?

Adware.Hebogo.SUF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment