Categories: Adware

Win32/Adware.Hebogo removal guide

The Win32/Adware.Hebogo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Hebogo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Adware.Hebogo?


File Info:

name: 99E71FD83F6CA8375EA6.mlwpath: /opt/CAPEv2/storage/binaries/c7f1045f92ee1dff93d407dd5e7b5bed91a18cd4783a38d41ea8650ea03296eccrc32: 5B6166A6md5: 99e71fd83f6ca8375ea61c892358523bsha1: 446dff28d89d35140bf5546afcda96d1d36f4e07sha256: c7f1045f92ee1dff93d407dd5e7b5bed91a18cd4783a38d41ea8650ea03296ecsha512: 9c6449c141940568f343c9be1ebda3be515007646f27bd714469de987a1ab7b6f7ecb6b13fd3fcb21193a948114ad57f70d00a9c0b2d9553ca5947a729c99522ssdeep: 3072:Cq8Qx/mjzrnkEX5k7pm7AgfVMEjwGysb:Cq8QEjzrkEX5k7pm7AgthwxQtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T175B3D63ABA047437EC9A45BA28799237691A3CB227409C6FB34997183530F4B75F631Fsha3_384: 3e1f545d064f3de53f7e63783acbb7928dd6d25dcc6318d189061f856e3dac505f43cfb3d193dd3d456c1fab91e46e6cep_bytes: 68b82c4000e8f0ffffff000000000000timestamp: 2021-11-03 00:33:37

Version Info:

Translation: 0x0412 0x04b0CompanyName: .ProductName: DtsMainConFileVersion: 2.00.0755ProductVersion: 2.00.0755InternalName: DtsMainConOriginalFilename: DtsMainCon.exe

Win32/Adware.Hebogo also known as:

Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
DrWeb Adware.Hebogo.33
MicroWorld-eScan Trojan.GenericKD.47536040
CAT-QuickHeal Adware.Hebogo.A3
McAfee PUP-FMT
Cylance Unsafe
Zillya Adware.Hebogo.Win32.3512
Sangfor Trojan.Win32.Save.a
K7AntiVirus Adware ( 004c4e051 )
K7GW Adware ( 004c4e051 )
Cyren W32/Hebogo.G.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Adware.Hebogo
ClamAV Win.Malware.Hebogo-9872088-0
BitDefender Trojan.GenericKD.47536040
Avast Win32:AdwareX-gen [Adw]
Ad-Aware Trojan.GenericKD.47536040
Sophos Generic ML PUA (PUA)
Comodo ApplicUnwnt.Win32.AdWare.Hebogo.STA@4rf3fi
McAfee-GW-Edition PUP-FMT
FireEye Generic.mg.99e71fd83f6ca837
Emsisoft Trojan.GenericKD.47536040 (B)
SentinelOne Static AI – Malicious PE
GData Trojan.GenericKD.47536040
Avira TR/VB.Downloader.Gen
MAX malware (ai score=84)
Antiy-AVL Trojan/Generic.ASMalwS.3370BDC
Arcabit Trojan.Generic.D2D557A8
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 PUP/Win32.MicroNames.R239879
VBA32 Adware.Hebogo
ALYac Trojan.GenericKD.47536040
Malwarebytes Adware.MicroNames
Rising Adware.Hebogo!1.B1D6 (CLASSIC)
Yandex Trojan.GenAsa!aeYSLtlPqMc
eGambit Unsafe.AI_Score_100%
Fortinet Adware/Hebogo
AVG Win32:AdwareX-gen [Adw]
Cybereason malicious.83f6ca
Panda Trj/Genetic.gen
MaxSecure Trojan.Malware.300983.susgen

How to remove Win32/Adware.Hebogo?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

What is “Malware.AI.1871717646”?

The Malware.AI.1871717646 is considered dangerous by lots of security experts. When this infection is active,…

10 mins ago

Malware.AI.4278300635 (file analysis)

The Malware.AI.4278300635 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Generic.Dialer.FFC8005B removal instruction

The Generic.Dialer.FFC8005B is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

Should I remove “RemoteAdmin.Win32.RAdmin.ad”?

The RemoteAdmin.Win32.RAdmin.ad is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

About “Lazy.189388” infection

The Lazy.189388 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan.MSIL.Kickler malicious file

The Trojan.MSIL.Kickler is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago