Trojan

Trojan-Downloader.Win32.Tovkater.bgfs removal guide

Malware Removal

The Trojan-Downloader.Win32.Tovkater.bgfs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Tovkater.bgfs virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
fiesta.younged.ru
mirraclez.club
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Tovkater.bgfs?


File Info:

crc32: CE54738E
md5: d4d6de7c6c78e3342cb92a4e2668453c
name: D4D6DE7C6C78E3342CB92A4E2668453C.mlw
sha1: c1df8e254a1f8221e76056402f409725e1e04a11
sha256: 5f9827ccc9267bf4a358c60a50f36926815bb49a09117e945e61aab927b360a4
sha512: b32125be536464b37c14a0034579cadb04dd851997f708b308c268609ed313c6e09494e0da599674a6e2ec459c3ab397ce954825af4303419a8de8d2390c34d0
ssdeep: 6144:eo4U3QIWoW8WJcUOn6Wl/5wG2G07rKNRsBKATUylLL+5M/C7fSDbgcY8t:ZQdoW8Mcv6OWBryurLL+q/MfQgGt
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

Comments: fgndtyxxx iInstall software 32
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Tovkater.bgfs also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0051eb601 )
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2487
CynetMalicious (score: 100)
ALYacDropped:Trojan.GenericKD.12667635
CylanceUnsafe
SangforTrojan.Win32.GenericKD.12667635
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Tovkater.bfc6b09e
K7GWTrojan-Downloader ( 0051eb601 )
Cybereasonmalicious.c6c78e
CyrenW32/Tovkater.L
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Tovkater-6936213-0
KasperskyTrojan-Downloader.Win32.Tovkater.bgfs
BitDefenderDropped:Trojan.GenericKD.12667635
NANO-AntivirusTrojan.Win32.InstallMonster.evxcms
MicroWorld-eScanDropped:Trojan.GenericKD.12667635
TencentWin32.Trojan-downloader.Tovkater.Wstq
Ad-AwareDropped:Trojan.GenericKD.12667635
SophosMal/Generic-S
ComodoApplication.Win32.InstallMonster.DX@7e9j3l
BitDefenderThetaGen:NN.ZexaF.34294.5y0@aigE5Up
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_HPGen-32
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.d4d6de7c6c78e334
EmsisoftDropped:Trojan.GenericKD.12667635 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
Antiy-AVLTrojan/Generic.ASMalwS.236892D
MicrosoftTrojan:Win32/Occamy.C
GDataDropped:Trojan.GenericKD.12667635
AhnLab-V3Trojan/Win32.Tovkater.R215387
Acronissuspicious
McAfeeArtemis!D4D6DE7C6C78
MAXmalware (ai score=97)
VBA32TrojanDownloader.Tovkater
MalwarebytesMalware.AI.3039103122
PandaTrj/Genetic.gen
TrendMicro-HouseCallPossible_HPGen-32
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!dgqaeC6Y+pQ
FortinetW32/Tovkater.IA!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Tovkater.bgfs?

Trojan-Downloader.Win32.Tovkater.bgfs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment