Adware

Adware.Hotbar.1 information

Malware Removal

The Adware.Hotbar.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Hotbar.1 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Hotbar.1?


File Info:

name: AB2A616A77063A85655F.mlw
path: /opt/CAPEv2/storage/binaries/6718237bbdb63b6a236d0e3009d2b76a71c1359840feb4d8a5cfc518ba1095e9
crc32: DFFC4CC5
md5: ab2a616a77063a85655f701f17f502d0
sha1: a4673da98edc444d1f62373b02288c0eea7ba7ee
sha256: 6718237bbdb63b6a236d0e3009d2b76a71c1359840feb4d8a5cfc518ba1095e9
sha512: 2324ab62179fd09d29c902025cc2af58d2dbf7fb3f1c7b18fe60272c1a096f7f8ba24887ca8dd335caa729eb4c67e82b8cb101507d12a0e3c09214d491440b63
ssdeep: 6144:403XFuM4nLSgTh2IcymPCHWIlm1Fa1asHPncBNOI9fHqhkI6+cl:4c1udnLSg03ymK2Ilm1F4a4kXPwCZxl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0341226C7351EC9E5A42D30162BCD5E191CFD33C42E79D43BD0681EAE363A6AF9140E
sha3_384: e3c85d17b480b7127c5c2d37a58a3dcb7fdf7b70d8b2ef75459708bec11b65d03856ed506b6a67f7dfe97acf2122b36f
ep_bytes: 60be00e044008dbe0030fbff57eb0b90
timestamp: 2012-03-08 15:56:25

Version Info:

FileDescription: Installer
FileVersion: 2.0.653.0
ProductVersion: 2.0.653.0
Translation: 0x0409 0x30ed

Adware.Hotbar.1 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.ScreenSaver.lwZX
DrWebAdware.Hotbar.811
MicroWorld-eScanGen:Variant.Adware.Hotbar.1
FireEyeGeneric.mg.ab2a616a77063a85
CAT-QuickHealPUA.Pinballcor.Gen
SkyhighBehavesLike.Win32.AdwareHotBar.dc
ALYacGen:Variant.Adware.Hotbar.1
Cylanceunsafe
ZillyaAdware.HotBar.Win32.710
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Browext.6359bc1b
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
VirITAdware.Win32.Zango.ACIA
SymantecAdware.Clkpotato!gen3
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Adware.HotBar.K
APEXMalicious
TrendMicro-HouseCallADW_HOTBAR_00000c2.TOMA
Paloaltogeneric.ml
ClamAVWin.Trojan.Adinstall-2
Kasperskynot-a-virus:WebToolbar.Win32.Zango.acia
BitDefenderGen:Variant.Adware.Hotbar.1
NANO-AntivirusRiskware.Win32.bqt.dvtokf
SUPERAntiSpywarePUP.Hotbar/Variant
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10bd99cb
EmsisoftGen:Variant.Adware.Hotbar.1 (B)
F-SecureAdware.ADWARE/Hotbar.aol
BaiduWin32.Trojan.HotBar.a
VIPREGen:Variant.Adware.Hotbar.1
TrendMicroHeurSpy_Zango-3
Trapminemalicious.moderate.ml.score
SophosHotbar (PUA)
IkarusTrojan.SuspectCRC
GDataGen:Variant.Adware.Hotbar.1
JiangminWebToolbar.Zango.ae
WebrootAdware.Hotbar
GoogleDetected
AviraADWARE/Hotbar.aol
VaristW32/HotBar.S.gen!Eldorado
Antiy-AVLRiskWare[WebToolbar]/Win32.Zango
Kingsoftmalware.kb.b.959
XcitiumApplicUnwnt.Win32.AdWare.Agent.DH@4mz9uu
ArcabitTrojan.Adware.Hotbar.1
ViRobotAdware.HotBar.239488
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Browext.gen
MicrosoftAdware:Win32/Hotbar
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.Hotbar.R14391
Acronissuspicious
McAfeeAdware-HotBar.f
VBA32SScope.TrojanInjector.xg
MalwarebytesGeneric.Malware.AI.DDS
RisingAdware.Hotbar!1.6AAD (CLOUD)
YandexTrojan.GenAsa!VcwWArfVvwc
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/ClickPotato.AA
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Adware.Hotbar.1?

Adware.Hotbar.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment