Adware

Adware.BrowserIO malicious file

Malware Removal

The Adware.BrowserIO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BrowserIO virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (22 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

imp.hyourmapview.com
getsearchbar.com
results.hyourmapview.com
x.ss2.us
www.bing.com
o.ss2.us
ocsp.rootg2.amazontrust.com
ocsp.rootca1.amazontrust.com
ocsp.sca1b.amazontrust.com
www.googletagmanager.com
cdn.onesignal.com
ocsp.digicert.com
crl3.digicert.com
crl4.digicert.com
ocsp.pki.goog
www.google-analytics.com
connect.facebook.net
d3ff8olul1r3ot.cloudfront.net
imp.onesearch.org
dap2y8k6nefku.cloudfront.net
s.symcd.com
s.symcb.com

How to determine Adware.BrowserIO?


File Info:

crc32: BC5E3366
md5: ca6ac935aa21313761648df1dd33b4be
name: CA6AC935AA21313761648DF1DD33B4BE.mlw
sha1: 6532cf4b2b71b944329221aebf2f8b4019f2c3ee
sha256: 51461876792e650528e0121239c0423543fb0ed72fe02e2b9436e0d71a4994f8
sha512: 3fa66dd25581efd1808dcf8c0ea611dd6babcc7c3c90c4667033a2cfe5493dd3986301de10854c8c79154fc3707bcd684d7e12891ae70abb551afafb1477853d
ssdeep: 24576:md3jC28zwCD00HxM0J2xTeFl84PldKBtQqIqr5klTBgv8jXu7Fmrve6:MzOzwCDJHPYdIlDeyqINBgUjXu7Fma6
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: (c) 2018 Polarity Technologies Ltd
FileVersion: 2.29.0.32
CompanyName: Polarity Technologies Ltd
ProductName: Desktop Search Bar
ProductVersion: 2.29.0.32
FileDescription: Desktop web search
OriginalFilename: SBInstaller
Translation: 0x0409 0x0000

Adware.BrowserIO also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebAdware.Spigot.149
MicroWorld-eScanDropped:Trojan.GenericKD.34104561
FireEyeGeneric.mg.ca6ac935aa213137
McAfeeArtemis!CA6AC935AA21
CylanceUnsafe
ZillyaTool.WebToolbar.Win32.23
AegisLabTrojan.Win32.Blocker.j!c
SangforSuspicious.Win32.Save.a
K7AntiVirusAdware ( 0053b2bb1 )
BitDefenderDropped:Trojan.GenericKD.34104561
K7GWAdware ( 0053b2bb1 )
Cybereasonmalicious.5aa213
APEXMalicious
AvastWin32:AdwareSig [Adw]
AlibabaAdWare:Win32/BrowserIO.20864567
NANO-AntivirusRiskware.Win32.WebSearch.fjeunv
RisingAdware.BrowserIO!1.B395 (CLASSIC)
Ad-AwareDropped:Trojan.GenericKD.34104561
EmsisoftDropped:Trojan.GenericKD.34104561 (B)
ComodoApplication.Win32.BrowserIO.C@7v8oon
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R002C0OC321
SophosBrowserIO (PUA)
IkarusAdWare.Spigot
AviraADWARE/OnlineIO.Gen
Antiy-AVLGrayWare/Win32.WinWrapper
MicrosoftBrowserModifier:Win32/SearchSetter
GridinsoftRansom.Win32.Blocker.sa
ArcabitTrojan.Generic.D20864F1
SUPERAntiSpywareAdware.Spigot/Variant
ZoneAlarmHEUR:Trojan-Ransom.Win32.Blocker.gen
GDataDropped:Trojan.GenericKD.34104561
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.WebToolbar.R239059
Acronissuspicious
VBA32Adware.WebSearch
ALYacDropped:Trojan.GenericKD.34104561
MAXmalware (ai score=87)
MalwarebytesAdware.BrowserIO
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.BrowserIO.C
TencentWin32.Trojan.Blocker.Szli
YandexTrojan.GenAsa!GaST7sujVuk
FortinetRiskware/BrowserIO
AVGWin32:AdwareSig [Adw]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Application.WebToolbar.d20

How to remove Adware.BrowserIO?

Adware.BrowserIO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment