Malware

What is “AdWare.Win32.DLBoost.bgmm”?

Malware Removal

The AdWare.Win32.DLBoost.bgmm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.DLBoost.bgmm virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine AdWare.Win32.DLBoost.bgmm?


File Info:

crc32: 1C7750F8
md5: 391d562833420658e69da2f66e32af73
name: 391D562833420658E69DA2F66E32AF73.mlw
sha1: e5e4f74f20864ff1d1951077e9cd560c308e5746
sha256: 1daee8588539f5ad3973aaa55c9606d4c8654d3c9f7fe75495d376d804e4396d
sha512: 7945df418e98771cff50974b8d7bc335f8b5e03d2ddd6370f0b5458a167daf8f9db97c1cbc0b7be43979f9908c6f1b427fb04f0ccb0b8f4f55208581e40d364d
ssdeep: 3072:ErV1c41UtsuvpnfqeubkzQYnnSUlc/6eh+UlbQx9HY4Ut4k7FXmcpvrKKwXLGev:Eo4UrnfqPkz9nSQc/4YbQL9Zk7FXmcAF
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Green elephants. All rights reserved.
InternalName: Install suite
FileVersion: 2.4.1.0
CompanyName:
Comments: Helps to install applications
ProductName: Free apps install suite
ProductVersion: 2.4.1.0
Translation: 0x0409 0x04b0

AdWare.Win32.DLBoost.bgmm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 005187a11 )
LionicAdware.Win32.DLBoost.2!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2381
CynetMalicious (score: 100)
ALYacDropped:Trojan.GenericKD.12443599
CylanceUnsafe
ZillyaAdware.DLBoost.Win32.3345
SangforTrojan.Win32.Tovkater.EP
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Tovkater.f2930711
K7GWTrojan-Downloader ( 005187a11 )
Cybereasonmalicious.833420
CyrenW32/Tovkater.P.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.EP
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Tovkater-6956309-0
Kasperskynot-a-virus:AdWare.Win32.DLBoost.bgmm
BitDefenderDropped:Trojan.GenericKD.12443599
NANO-AntivirusTrojan.Win32.InstallMonster.ethpzf
MicroWorld-eScanDropped:Trojan.GenericKD.12443599
TencentWin32.Adware.Dlboost.Liqv
Ad-AwareDropped:Trojan.GenericKD.12443599
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.DF@7e42g4
BitDefenderThetaGen:NN.ZexaF.34266.sC0@aKRPF0ai
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0PG721
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.391d562833420658
EmsisoftDropped:Trojan.GenericKD.12443599 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
Antiy-AVLTrojan/Generic.ASMalwS.2234DF8
MicrosoftTrojan:Win32/Occamy.C1D
GDataDropped:Trojan.GenericKD.12443599
AhnLab-V3PUP/Win.BundleInstaller.R419279
Acronissuspicious
McAfeeArtemis!391D56283342
MAXmalware (ai score=100)
VBA32TrojanDownloader.Tovkater
MalwarebytesMalware.AI.3039103122
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R011C0PG721
RisingTrojan.Generic@ML.100 (RDML:2p815G5f2T4i6dbmxSXcsg)
YandexTrojan.DL.Tovkater!tPGdgok0ZCs
FortinetW32/Tovkater.EN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove AdWare.Win32.DLBoost.bgmm?

AdWare.Win32.DLBoost.bgmm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment