Malware

AdWare.Win32.DLBoost.bfcz removal

Malware Removal

The AdWare.Win32.DLBoost.bfcz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DLBoost.bfcz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Created network traffic indicative of malicious activity

Related domains:

wpad.local-net
persist.tippled.ru
duckandbear.top

How to determine AdWare.Win32.DLBoost.bfcz?


File Info:

name: 09494A02117F83752D74.mlw
path: /opt/CAPEv2/storage/binaries/22d94a9f4b9e3a846e49c482eef9bacef6b4d020c794561e36e527ee8b002526
crc32: D19E1F4F
md5: 09494a02117f83752d74cb86db04d903
sha1: cd39eb561f41e53505101879459c2ba176f11964
sha256: 22d94a9f4b9e3a846e49c482eef9bacef6b4d020c794561e36e527ee8b002526
sha512: 594746be8e78d1daa3b58683a71be7b27406905c752c6b7382250bb5930d5d8f8cca4045be28c4ba7cecb6b423f2c65c4d8875a3bc6936c76b6eee8d1ba31494
ssdeep: 6144:zr2R6xzRukIg/MqlgvmYrXPiqEMkGF5nE:TRukYqlgvnXPi9Kq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC1402017660C22BEAE587711F7F7BA6DEB3E1A16C60978313805E4F3CA17C0591E75A
sha3_384: ef88c8f6fa083807d20511f8f181e77822a5d22650b8fc1e1be4919598e756dbf3246ab1ef2de3d7e1f226afcb294b4d
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2017-08-01 00:35:13

Version Info:

Comments: App manager
CompanyName: Orange lime
FileVersion: 2.3.1.4
InternalName: Tools manager
LegalCopyright: Orange lime. All rights reserved.
ProductName: Istall tools manager
ProductVersion: 2.3.1.4
Translation: 0x0409 0x04b0

AdWare.Win32.DLBoost.bfcz also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jatif.722
FireEyeGeneric.mg.09494a02117f8375
McAfeeArtemis!09494A02117F
CylanceUnsafe
ZillyaAdware.DLBoost.Win32.3344
SangforTrojan.Win32.Tovkater.EL
K7AntiVirusUnwanted-Program ( 00587b2b1 )
AlibabaTrojanDownloader:Win32/Tovkater.854f6476
K7GWUnwanted-Program ( 00587b2b1 )
Cybereasonmalicious.2117f8
BitDefenderThetaGen:NN.ZexaF.34084.hy0@aaL0lLei
CyrenW32/Tovkater.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Tovkater.EL
TrendMicro-HouseCallTROJ_GEN.R067C0PL321
Paloaltogeneric.ml
ClamAVWin.Dropper.Tovkater-6646735-0
Kasperskynot-a-virus:AdWare.Win32.DLBoost.bfcz
BitDefenderGen:Variant.Jatif.722
NANO-AntivirusTrojan.Win32.Tovkater.eteiqh
AvastWin32:Malware-gen
TencentWin32.Adware.Dlboost.Eyj
Ad-AwareGen:Variant.Jatif.722
EmsisoftApplication.AdLoad (A)
Comodofls.noname@0
DrWebTrojan.InstallMonster.2368
VIPREAmonetize (fs)
TrendMicroTROJ_GEN.R067C0PL321
McAfee-GW-EditionGenericR-KNQ!5F15FE8AAF82
SophosGeneric PUA MN (PUA)
JiangminTrojanDownloader.Tovkater.ai
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1108483
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.222C240
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftSoftwareBundler:Win32/DirectDownloader
APEXMalicious
GDataGen:Variant.Jatif.722
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DLBoost.R210363
VBA32Trojan.Wacatac
ALYacGen:Variant.Jatif.722
MalwarebytesPUP.Optional.BundleInstaller
RisingTrojan.Generic@ML.100 (RDML:TZstGLaJZ5ogberJHe/VnA)
SentinelOneStatic AI – Malicious PE
FortinetW32/Tovkater.EN!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove AdWare.Win32.DLBoost.bfcz?

AdWare.Win32.DLBoost.bfcz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment