Adware

About “Adware.HahoMedia” infection

Malware Removal

The Adware.HahoMedia is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.HahoMedia virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Adware.HahoMedia?


File Info:

name: 1B44898A833FDE1D0CE6.mlw
path: /opt/CAPEv2/storage/binaries/6ecfd45519bb2c078eecf4de3c810b4a123c9e9020d4914451ec0649b9982f7e
crc32: 18B7AE2C
md5: 1b44898a833fde1d0ce6dbc3806942a4
sha1: 008b04b09918fd065e8b8af1ccad6b10b35adc76
sha256: 6ecfd45519bb2c078eecf4de3c810b4a123c9e9020d4914451ec0649b9982f7e
sha512: 4d54bc127d29416ce0523217feebe2dd49ca6f729dd6b2e444c05c312037fd4c40e444189f19f01b27a54b74ebc05edad1b370653fb86c46fce85069e6cd80dd
ssdeep: 3072:SLPTB0ViQXsrqohMeWQZX3FjpvFOYD2bJVCi8Ea93PEApzqVdMQ+:S/QiQXC/hMmp8KiVCixGHQ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12934F107BAD79139C062B6F45E32D061A53BBE662834601572BD3E8D9F37247DC0A36E
sha3_384: 8a30ea297f24b4aa9622c626d9655d9efb5ab0a66ebc7a706fa24eac78db4a177509c2ec789ee5db64f7ff6b978663bf
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Bug Fixxer
FileDescription: BugFixxer Setup Setup
FileVersion: 18.5.26.1
LegalCopyright: Copyright © Bug Fixxer @ 2016.
ProductName: BugFixxer Setup
ProductVersion: 18.5.26.1
Translation: 0x0000 0x04b0

Adware.HahoMedia also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005207b21 )
K7GWAdware ( 005207b21 )
ESET-NOD32a variant of MSIL/Adware.Hahomeida.D
NANO-AntivirusRiskware.Win32.Hahomeida.fgachc
AvastFileRepMalware
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.dc
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
MalwarebytesAdware.HahoMedia
APEXMalicious
SentinelOneStatic AI – Suspicious PE
FortinetAdware/Hahomeida
AVGFileRepMalware

How to remove Adware.HahoMedia?

Adware.HahoMedia removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment