Malware

Win32:BogEnt removal

Malware Removal

The Win32:BogEnt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:BogEnt virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Win32:BogEnt?


File Info:

name: 8004565B0346583F1EE1.mlw
path: /opt/CAPEv2/storage/binaries/c31a64b5c6560e8544ae47c1e2076f1c701f1e9daa02edfe67ab41d15296a0a4
crc32: 50B24533
md5: 8004565b0346583f1ee11b7f3978a40c
sha1: 331e7a6c147cb915182894bafd6fc01ecf6be318
sha256: c31a64b5c6560e8544ae47c1e2076f1c701f1e9daa02edfe67ab41d15296a0a4
sha512: 21f50d98d254ce8e256a03c5cd56a2df6bc866d02e9f4ebf995d90eb820f6a531bda69ac06427d8a68df8ba1247bbe71df239e9a4224d83abaf45bc928539700
ssdeep: 49152:UElGr85FkBYimiVOSp2QWRMFIvRbX64IFOh5PMq2twVPyIpWOUNmI3Hmj75Veam9:avmttuTwcI6mI
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1E8F59E57B7A800D4C57AC13CD9468A17E7F1B42607329FDF16A84AB90F23AE16E3E711
sha3_384: bffcf26b669150ecab99fb5b5bea59e802efdc04340c6d238e4e751785b71339230be7b6df05d04fcfebf0529e588789
ep_bytes: 00000000000000000000000000000000
timestamp: 2021-04-06 10:25:45

Version Info:

0: [No Data]

Win32:BogEnt also known as:

LionicRiskware.Win64.Miner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.80117
FireEyeGeneric.mg.8004565b0346583f
McAfeeArtemis!8004565B0346
SangforVirus.Win32.Save.a
AlibabaRiskWare:Win64/Miners.97cb1f72
K7GWAdware ( 00535a971 )
K7AntiVirusAdware ( 00535a971 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.IZ potentially unwanted
Kasperskynot-a-virus:HEUR:RiskTool.Win64.Miner.b
BitDefenderTrojan.GenericKDZ.80117
AvastWin32:BogEnt [Susp]
Ad-AwareTrojan.GenericKDZ.80117
EmsisoftTrojan.GenericKDZ.80117 (B)
ZillyaTool.Miner.Win64.375
TrendMicroTROJ_GEN.R03BC0WKL21
McAfee-GW-EditionBehavesLike.Win64.BadFile.wh
SophosGeneric PUA DD (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.80117
JiangminRiskTool.Miner.ahn
Antiy-AVLTrojan/Generic.ASMalwS.34D4995
ViRobotTrojan.Win32.Z.Coinminer.3508736.C
MicrosoftPUA:Win32/CoinMiner
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Miner3.R425063
ALYacTrojan.GenericKDZ.80117
MAXmalware (ai score=87)
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R03BC0WKL21
RisingHackTool.CoinMiner!1.D760 (CLASSIC)
IkarusPUA.CoinMiner
MaxSecureTrojan.Malware.74288758.susgen
FortinetAdware/Miner
AVGWin32:BogEnt [Susp]
Cybereasonmalicious.c147cb
PandaTrj/CI.A

How to remove Win32:BogEnt?

Win32:BogEnt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment